CVE-2026-46409
OpenYak RCE via Local HTTP API Insecure Binding
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
The OpenYak desktop application has a vulnerability where its local HTTP API lacks server-side validation, allowing a malicious webpage visited by a user to execute arbitrary shell commands and exfiltrate sensitive data. This could lead to remote code execution and compromise of user information.