A vulnerability marked as critical has been reported in OpenHands up to 0.62.0. The affected element is the function
initialize_repo of the file OpenHands/resolver/send_pull_request.py. This manipulation causes command injection.
This vulnerability is registered as CVE-2026-19022. Remote exploitation of the attack is possible. No exploit is available.
The vendor deleted the original GitHub issue report. It appears that the affected path/file got removed in version 1.7.0.