CVE-2026-33718Disclosure(openhands / openhands)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openhands openhands systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in the `get_git_diff()` method at `openhands/runtime/utils/git_handler.py:134`. The `path` parameter from the `/api/conversations/{conversation_id}/git/diff` API endpoint is passed unsanitized to a shell command, allowing authenticated attackers to execute arbitrary commands in the agent sandbox. The user is already allowed to instruct the agent to execute commands, but this bypasses the normal channels. Version 1.5.0 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openhands

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-27); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openhands

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-27: 2Mentions · 2026-04-10: 1Mentions · 2026-08-27: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-08-27: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-10: 1Technical Details · 2026-08-27: 103-2704-1008-27
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-272
Disclosure2
2026-04-101
Patch1
2026-08-271
Patch1
Full discourse4 posts
  • 0xBaron | AI Security@0xPixelBaron
    Patch

    OpenHands released v1.16.0 today. Before looking at the feature list, check the version boundary. Its official advisory for CVE-2026-33718 lists OpenHands 1.4.0 and earlier as affected by command injection in the Git diff handler. The fix landed in 1.5.0.

    Post summary

    OpenHands CVE-2026-33718 is a command injection flaw in the Git diff handler affecting <1.5.0, fixed in 1.5.0; users should upgrade to the patched version.

    20010102
    6.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33718 OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in the `get_git_diff()` method at `openhands/runt… https://www.cve.org/CVERecord?id=CVE-2026-33718

    Post summary

    CVE-2026-33718 is disclosed as a command injection flaw in OpenHands' get_git_diff() method, with no proof of concept, exploitation, or patch details provided.

    00010127
    56.9K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2026-33718 (CVSS 7.6) - Command Injection in OpenHands AI dev platform v1.5.0+. Authenticated attackers can execute arbitrary commands via unsanitized path parameter. Patch available in v1.5.0. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/wwCQqa9Ap5

    Post summary

    A command‑injection vulnerability (CVE-2026-33718) affecting OpenHands AI platform has been disclosed, with a patch released in v1.5.0; no proof of concept, exploit, or active exploitation claims are present.

    0000052
    10 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33718 📊 Severity: 7.6 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33718 #CVE-2026-33718 #CVE #High #CyberSecurity #InfoSec https://t.co/BC4NC9nZCh

    Post summary

    A new CVE (CVE-2026-33718) has been announced with a severity of 7.6 and high risk, affecting multiple unspecified products, but no PoC, exploit, or patch information is provided.

    0000030
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenhandsopenhands-python-

Explore more