OpenHarmony Arbitrary Code Execution Vulnerability

Vulnerability

A vulnerability in OpenHarmony versions 6.0 and prior allows local attackers to execute arbitrary code. This issue is classified as a use-after-free vulnerability in the filemanagement_storage_service component, specifically in the OpenHarmony-v5.1.0-Release branch.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code, potentially allowing an attacker to execute malicious payloads or commands on the affected system.

Remediation

Users can apply the patch available in the OpenHarmony filemanagement_storage_service repository, specifically in the pull request linked in the references.

Added: May 19, 2026, 4:42 AM
Updated: May 19, 2026, 4:42 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
2.7
remediation
0.0
relevance
8.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.