CVE-2026-88624
Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload.
- Published Sep 22, 2026
- CVSS 9.1 critical
- 0.3% chance of exploitation in the next 30 days (EPSS)