Impact
A missing path validation check in the Worktree.remove component of openCode v1.18.26 allows an attacker to craft a payload that specifies any directory path. The component will then perform a recursive delete of that path, resulting in loss of files and directories. This flaw can lead to significant data loss and service disruption, as critical files may be removed without permission. The weakness is a failure of input validation that permits destructive action on the filesystem.
Affected Systems
The affected product is openCode, specifically version 1.18.26. No additional vendor or product information is supplied by the CVE data.
Risk and Exploitability
The vulnerability can be exploited by sending a crafted request to the Worktree.remove endpoint, either locally or remotely, if the application is exposed. Because the flaw does not require additional privileges beyond those granted to the victim user, the reach is potentially wide. No CVSS or EPSS scores are available, so the risk is inferred to be high due to the destructive nature of the ability to delete arbitrary directories. The issue is not listed in the CISA KEV catalog. The likelihood of exploitation depends on the exposure of the affected component and the overall security posture of the environment.
OpenCVE Enrichment