CVE-2026-19022

A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pull_request.py. This manipulation causes command injection. Remote exploitation of the attack is possible. The vendor deleted the original GitHub issue report. It appears that the affected path/file got removed in version 1.7.0.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-06 09:16

Updated : 2026-08-12 21:00


NVD link : CVE-2026-19022

Mitre link : CVE-2026-19022

CVE.ORG link : CVE-2026-19022


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')