VYPR

openyak

by Openyak

CVEs (1)

  • CVE-2026-46409CriAug 7, 2026
    risk 0.62cvss 9.6epss

    OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:` (commonly 19141) without server-side Origin validation, loopback…