CVE-2026-88624
EUVD-2026-8485622.09.2026, 20:17
Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.