Horizon Alert
Summary of the vulnerability and why it matters
This advisory details a critical vulnerability in the Worktree.remove component of openCode that could allow unauthorized recursive deletion of directories through a malicious input. While the technology itself is primarily used in developer environments, the potential for data loss necessitates understanding its relevance to our organization. The main concern is confirming if our use of this component exposes us to this risk.
- Malicious input can delete directories.
- Confirms our exposure to this risk.
- Assess relevance to our development tools.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending a specially crafted payload to the Worktree.remove component. This component, if exposed, might allow an unauthenticated user to trigger arbitrary recursive directory deletions, potentially leading to system compromise.
- No authentication needed.
- Trigger by crafted deletion payload.
- Arbitrary recursive directory deletion.
Live Threat
Current exploitation, exposure, and threat context
A missing path validation in the Worktree.remove component could allow an attacker to execute arbitrary recursive directory deletion via a crafted payload when supported by the advisory.
- Malicious code execution and data deletion.
- Crafted payload exploits directory traversal.
- Potential for system compromise and data loss.
Operational Fix
Recommended remediation, mitigation, and detection steps
The openCode Worktree component is vulnerable to arbitrary recursive directory deletion. This issue impacts users of openCode, and the first practical step is to identify all instances of openCode within your environment, confirm their reachability and business criticality, and then engage the appropriate teams for remediation planning.
- Identify openCode instances and owners.
- Verify external reachability and impact.
- Plan remediation based on risk.