CVE-2026-55743: The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privi...

Added to the CISA Known Exploited Vulnerabilities catalog on 17 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.6.

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. Two flaws in src/openhuman/security/policy.rs combine: (1) is_args_safe()...

Required action: Review and patch if applicable to your AI infrastructure.