Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pull_request.py. This manipulation causes command injection. Remote exploitation of the attack is possible. The vendor deleted the original GitHub issue report. It appears that the affected path/file got removed in version 1.7.0. | |
| Title | OpenHands send_pull_request.py initialize_repo command injection | |
| First Time appeared |
Openhands
Openhands openhands |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:openhands:openhands:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openhands
Openhands openhands |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-06T08:15:08.598Z
Reserved: 2026-08-05T22:01:21.353Z
Link: CVE-2026-19022
No data.
No data.
No data.
OpenCVE Enrichment
No data.