THREAT OPS › Threat News › [GHSA] GHSA-52gf-6rpq-fgmx (high) — OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
[GHSA] GHSA-52gf-6rpq-fgmx (high) — OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
GHSA-52gf-6rpq-fgmx Severity: high CVE: CVE-2026-73841
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
### Summary
The OpenChoreo API server (`openchoreo-api`) authorized requests to its exec and wirelogs endpoints against the project supplied by the caller in the request, rather than against the project that actually
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-73841cve
Original source: https://github.com/advisories/GHSA-52gf-6rpq-fgmx