THREAT OPS › Threat News › [NVD] CVE-2026-46409 (CRITICAL 9.6) — OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without server-side Origin validation, loopback authen
[NVD] CVE-2026-46409 (CRITICAL 9.6) — OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without server-side Origin validation, loopback authen
CVE-2026-46409 CVSS: 9.6 CRITICAL Published: 2026-08-07T23:17:03.243
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without server-side Origin validation, loopback authentication, or Content-Type enforcement, and with a
Indicators of compromise
- CVE-2026-46409cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-46409