MCPA-2026-0059
mediumrce-vectorsCVSS 6.3
OpenHands resolver command injection in initialize_repo (CVE-2026-19022)
OpenHands (PyPI: openhands-ai) up to 0.62.0: the initialize_repo function in resolver/send_pull_request.py passes attacker-influenced input into a shell command, allowing remote command injection through the resolver's pull-request flow. The vendor deleted the original issue report; the affected file was removed by the 1.x restructure (reported as gone in 1.7.0), so the range is recorded as last_affected 0.62.0 per the public advisory.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | openhands-ai | >= 0, <= 0.62.0 |
Identifiers
CVE-2026-19022GHSA-f5cw-432q-pfqrCWE-74
References
- advisory https://github.com/advisories/GHSA-f5cw-432q-pfqr
- web https://nvd.nist.gov/vuln/detail/CVE-2026-19022
- web https://github.com/OpenHands/OpenHands/issues/14903
- web https://vuldb.com/cve/CVE-2026-19022
Timeline
- Published: 2026-08-06