PatchSiren

openchoreo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH openchoreo CVE published 2026-08-13

CVE-2026-73841

The OpenChoreo platform, a complete open-source developer platform for Kubernetes, is vulnerable to unauthorized command execution and wirelog access. This vulnerability, tracked as CVE-2026-73841, stems from improper authorization in internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go. Specifically, the platform incorrectly uses the caller-supplied project qu [truncated]