What is CVE-2026-19022?
A command injection vulnerability was identified in the 'initialize_repo' function of 'send_pull_request.py' in OpenHands up to version 0.62.0. This allows remote code execution. Immediate update to the latest version is recommended.
Azərbaycanca: OpenHands (0.62.0-ə qədər) tətbiqində 'send_pull_request.py' faylındakı 'initialize_repo' funksiyasında command injection zəifliyi aşkarlanıb. Bu, uzaqdan kod icrasına imkan verir. Dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ1
Which versions of OpenHands are affected by CVE-2026-19022?
All versions of OpenHands up to 0.62.0 are affected by the command injection vulnerability in the 'initialize_repo' function in 'send_pull_request.py'.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.