VYPR

openhuman

by Tinyhumansai

CVEs (1)

  • CVE-2026-55743Jun 17, 2026
    risk 0.00cvss epss

    The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. Two flaws in src/openhuman/security/policy.rs combine:…