← Back to search

CVE-2026-88624

9.1 CRITICALpublic exploit available

Published 2026-09-22 · Updated 2026-09-24

AI risk analysis

Summary
This vulnerability allows attackers to execute arbitrary recursive directory deletion by exploiting missing path validation in the Worktree.remove component of openCode v1.18.26, posing a critical risk to system integrity.
Exploitability
Exploitation is relatively straightforward given a crafted payload, requiring the attacker to have access to the affected component.
Blast radius
If exploited, this could result in the complete loss of data and potentially the entire filesystem of the affected system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to openCode v1.18.27 or later.
rcefilesystemdirectorycritical

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Weaknesses

CWE-22

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.