CVE-2026-55743

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-17 15:17

Updated : 2026-08-10 12:17


NVD link : CVE-2026-55743

Mitre link : CVE-2026-55743

CVE.ORG link : CVE-2026-55743


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-184

Incomplete List of Disallowed Inputs