PatchSiren

openyak CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL openyak CVE published 2026-08-07

CVE-2026-46409

CVE-2026-46409 is a critical vulnerability in OpenYak, a local-first agent runtime for reliable tool-using models. The vulnerability allows for remote code execution (RCE) via an HTTP API bound to localhost without proper security measures, enabling an attacker to execute arbitrary shell commands, shut down the service, and exfiltrate sensitive data.