Medium severity5.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108721
CVE-2026-108721
Description
Open Computer Use through 1.0.0 on macOS contains an improper case sensitivity handling vulnerability that allows local MCP callers to bypass the password-manager denylist using case-variant bundle identifiers. Attackers, including prompt-injected model turns, can pass identifiers like com.1Password.1Password to get_app_state and action tools to read accessibility trees, capture screenshots, and drive unlocked password manager interfaces.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=1.0.0+ 1 more
- (no CPE)range: <=1.0.0
- (no CPE)
- Range: <=1.0.0
Patches
Vulnerability mechanics
References
4- github.com/iFurySt/open-codex-computer-use/blob/8a3a7dec06402db2d760368cb24676ad3ba42c49/packages/OpenComputerUseKit/Sources/OpenComputerUseKit/AppDiscovery.swiftnvd
- github.com/iFurySt/open-codex-computer-use/blob/8a3a7dec06402db2d760368cb24676ad3ba42c49/packages/OpenComputerUseKit/Sources/OpenComputerUseKit/AppDiscovery.swiftnvd
- hackmd.io/@haind/rJHI_S6IiMlnvd
- www.vulncheck.com/advisories/open-computer-use-through-1.0.0-denylist-bypass-via-case-variant-bundle-idnvd
News mentions
0No linked articles in our index yet.