THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-52gf-6rpq-fgmx (high) — OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints

[GHSA] GHSA-52gf-6rpq-fgmx (high) — OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints

medgithub_advisoriesPublished 2026-09-02

GHSA-52gf-6rpq-fgmx Severity: high CVE: CVE-2026-73841

OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints

### Summary

The OpenChoreo API server (`openchoreo-api`) authorized requests to its exec and wirelogs endpoints against the project supplied by the caller in the request, rather than against the project that actually

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-52gf-6rpq-fgmx