CVE-2026-55743
OpenHuman Desktop Agent Command Allowlist Bypass Leads to Remote Code Execution.
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
A vulnerability in the OpenHuman desktop agent allows bypassing its command allowlist to execute arbitrary OS commands with user privileges. This can occur when the agent processes malicious content, leading to potential remote code execution, data exfiltration, and system compromise. Confirmation of the agent's presen