---
id: CVE-2026-55743
title: >-
  The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop
  agent through 0.54.0 (default Supervised security policy) can be bypassed to
  execute arbitrary OS commands with the privileges of the desktop user.
summary: >-
  The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop
  agent through 0.54.0 (default Supervised security policy) can be bypassed to
  execute arbitrary OS commands with the privileges of the desktop user.
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
  - CWE-184
published: '2026-06-17'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55743'
references:
  - url: 'https://github.com/tinyhumansai/openhuman'
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
  - url: >-
      https://github.com/tinyhumansai/openhuman/blob/v0.53.49-staging/src/openhuman/security/policy.rs
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
  - url: >-
      https://github.com/tinyhumansai/openhuman/commit/60050aa09a870f53ed7e4cd40ed41fd2860329e7
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
tags:
  - nvd
epss: 0.00572
epssPercentile: 0.44993
ingestedAt: '2026-08-10T12:39:46.971Z'
---

## Overview

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
