PT-2026-68454 · Openhands · Openhands
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenHands versions prior to 0.62.1
Description
Remote command injection is possible through the
initialize repo() function located in the OpenHands/resolver/send pull request.py file. Command injection is a flaw that allows an attacker to execute arbitrary operating system commands on the server.Recommendations
Update to a version later than 0.62.0.
As a temporary workaround, restrict access to the
initialize repo() function until the software is updated.Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openhands