CRITICAL
openyak
CVE published 2026-08-07
CVE-2026-46409
CVE-2026-46409 is a critical vulnerability in OpenYak, a local-first agent runtime for reliable tool-using models. The vulnerability allows for remote code execution (RCE) via an HTTP API bound to localhost without proper security measures, enabling an attacker to execute arbitrary shell commands, shut down the service, and exfiltrate sensitive data.