CVE-2026-19022: OpenHands send_pull_request.py initialize_repo command injection
A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initializerepo of the file OpenHands/resolver/sendpullrequest.py. This manipulation causes command injection. Remote exploitation of the attack is possible. The vendor deleted the original GitHub issue report. It appears that the affected path/file got removed in version 1.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenHandsto a version that resolves this vulnerability.Fixed in 1.7.0 - Compensating control
Given remote exploitation is possible via the OpenHands/resolver/send_pull_request.py initialize_repo command injection, restrict network/firewall access to any externally reachable OpenHands instance/endpoints that could trigger send_pull_request.py initialize_repo until upgraded to 1.7.0.
Event History
Frequently Asked Questions
What is CVE-2026-19022?
CVE-2026-19022 is a command injection vulnerability in OpenHands that affects versions up to 0.62.0 through the initialize_repo function.
What is the severity of CVE-2026-19022?
CVE-2026-19022 has a medium severity rating of 6.3.
How do I fix CVE-2026-19022?
To mitigate CVE-2026-19022, consider upgrading OpenHands to a patched version beyond 0.62.0.
What impact does CVE-2026-19022 have?
CVE-2026-19022 allows for remote command injection, potentially leading to unauthorized actions on the system.
Who is affected by CVE-2026-19022?
Any user running OpenHands versions up to 0.62.0 is at risk from CVE-2026-19022.