{"id":"CVE-2026-88624","published":"2026-09-22T20:17:11.260","lastModified":"2026-09-24T21:08:55.030","description":"Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://github.com/MyselfYangjz/vulnReport/issues/2","tags":[]}],"exploitRefs":[{"url":"https://github.com/MyselfYangjz/vulnReport/issues/2","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows attackers to execute arbitrary recursive directory deletion by exploiting missing path validation in the Worktree.remove component of openCode v1.18.26, posing a critical risk to system integrity.","exploitability":"Exploitation is relatively straightforward given a crafted payload, requiring the attacker to have access to the affected component.","blast_radius":"If exploited, this could result in the complete loss of data and potentially the entire filesystem of the affected system.","remediation":"Upgrade to openCode v1.18.27 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","filesystem","directory","critical"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:51:35.705Z"}}