Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 08 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openyak
Openyak openyak |
|
| Vendors & Products |
Openyak
Openyak openyak |
Fri, 07 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without server-side Origin validation, loopback authentication, or Content-Type enforcement, and with a wildcard CORS policy. Any webpage a user visits while OpenYak is running can issue cross-origin requests to this local server — the browser acts as a proxy into loopback, bypassing OS-level network isolation. Chained, this lets a malicious page execute arbitrary shell commands on the host (RCE) via the build agent with `permission_presets.bash=true`, shut down the service, and exfiltrate chat history and account PII — with no user interaction beyond opening the page. Version 1.1.3 patches the issue. | |
| Title | OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution | |
| Weaknesses | CWE-306 CWE-346 CWE-352 CWE-94 CWE-942 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-11T01:19:03.951Z
Reserved: 2026-05-13T21:04:10.932Z
Link: CVE-2026-46409
Updated: 2026-08-11T01:18:59.886Z
Status : Received
Published: 2026-08-07T23:17:03.243
Modified: 2026-08-11T02:16:51.010
Link: CVE-2026-46409
No data.
OpenCVE Enrichment
Updated: 2026-08-08T20:40:15Z