7.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Description
OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in the `get_git_diff()` method at `openhands/runtime/utils/git_handler.py:134`. The `path` parameter from the `/api/conversations/{conversation_id}/git/diff` API endpoint is passed unsanitized to a shell command, allowing authenticated attackers to execute arbitrary commands in the agent sandbox. The user is already allowed to instruct the agent to execute commands, but this bypasses the normal channels. Version 1.5.0 fixes the issue.
Basic Information
ID
CVE-2026-33718
Source
GitHub_M
Published
Mar 27, 2026 at 00:12
Modified
Mar 27, 2026 at 20:04
Affected Product
Vendor
OpenHands
Product
OpenHands
Version
< 1.5.0
Affected Versions
OpenHands OpenHands < 1.5.0