CVE-2026-88624

Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload.

  • Published Sep 22, 2026
  • CVSS 9.1 critical
  • 0.3% chance of exploitation in the next 30 days (EPSS)

CVE-2026-88624 at the National Vulnerability Database