A vulnerability described as critical has been identified in OpenHands up to 1.4.x. This affects the function get_git_diff of the file openhands/runtime/utils/git_handler.py of the component API Endpoint. Executing a manipulation of the argument path can lead to os command injection. This vulnerability is handled as CVE-2026-33718. The attack can be executed remotely. There is not any exploit available. Upgrading the affected component is recommended.
| Vendor | Product | Versions |
|---|---|---|
| openhands | OpenHands | < 1.5.0, 1.4.x |
Updated product name to OpenHands, changed severity to CRITICAL, added affected version 1.4.x, and noted that the vulnerability is actively exploited.
Initial creation