HKUDS OpenHarness Session Key Derivation Vulnerability Allowing Session Hijacking

Vulnerability

A session key derivation vulnerability has been identified in HKUDS OpenHarness versions prior to the PR #159 remediation. This vulnerability allows authenticated users in shared chats or threads to hijack the sessions of other users. The issue arises from a shared session key that does not verify sender identity, enabling attackers to reuse another user's conversation state and disrupt their ongoing tasks by interfering with the same session boundary within the shared chat or thread.

Impact

Exploitation of this vulnerability could lead to unauthorized session hijacking, allowing attackers to impersonate other users and disrupt their activities by interfering with their conversation state and active tasks.

Reproduction

To reproduce this vulnerability, an authenticated user can join a shared chat or thread. Once in the same chat or thread, the user can exploit the shared session key, which lacks sender identity verification, to hijack another user's session. This can be done by colliding into the same session boundary through the shared chat or thread scope, thereby taking over the other user's conversation state and active tasks.

Remediation

Users are advised to update to the version of HKUDS OpenHarness that includes the PR #159 remediation.

Added: Apr 20, 2026, 10:21 PM
Updated: Apr 20, 2026, 10:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.8
remediation
0.0
relevance
6.3
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.