External risk intelligence

openCode Worktree Arbitrary Recursive Directory Deletion

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-88624

The vulnerability involves local file system path manipulation within a worktree component. Such tools are typically used in developer-only environments, build pipelines, or local workstations and are not designed to be exposed as public-facing network services.

Path Traversal

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in the Worktree.remove component of openCode that could allow unauthorized recursive deletion of directories through a malicious input. While the technology itself is primarily used in developer environments, the potential for data loss necessitates understanding its relevance to our organization. The main concern is confirming if our use of this component exposes us to this risk.

  • Malicious input can delete directories.
  • Confirms our exposure to this risk.
  • Assess relevance to our development tools.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted payload to the Worktree.remove component. This component, if exposed, might allow an unauthenticated user to trigger arbitrary recursive directory deletions, potentially leading to system compromise.

  • No authentication needed.
  • Trigger by crafted deletion payload.
  • Arbitrary recursive directory deletion.

Live Threat

Current exploitation, exposure, and threat context

A missing path validation in the Worktree.remove component could allow an attacker to execute arbitrary recursive directory deletion via a crafted payload when supported by the advisory.

  • Malicious code execution and data deletion.
  • Crafted payload exploits directory traversal.
  • Potential for system compromise and data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

The openCode Worktree component is vulnerable to arbitrary recursive directory deletion. This issue impacts users of openCode, and the first practical step is to identify all instances of openCode within your environment, confirm their reachability and business criticality, and then engage the appropriate teams for remediation planning.

  • Identify openCode instances and owners.
  • Verify external reachability and impact.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is openCode and how is it used?

openCode is a software utility designed for managing development environments and source control tasks. It provides a Worktree component that developers use to organize, remove, or modify project directory structures efficiently. Because it handles file system operations directly, it is typically deployed within local workstations, build servers, or isolated development pipelines rather than on public-facing servers.

What does CWE-22 mean for CVE-2026-88624?

CVE-2026-88624 is classified as CWE-22, which is an Improper Limitation of a Pathname to a Restricted Directory vulnerability. In simpler terms, the software fails to properly verify or restrict the file paths provided to it. Because of this weakness, an attacker can supply a specially crafted input that tricks the Worktree.remove component into deleting directories outside of its intended scope.

How can an attacker trigger this directory deletion?

An attacker triggers this flaw by sending a crafted payload to the Worktree.remove component. The vulnerability requires a specific, malicious input designed to exploit the missing path validation. Simply using the software for its normal, intended file management functions does not trigger the bug; the system only performs this destructive action when it processes specifically malformed data.

Is my environment at risk from this CVE?

According to Halo Surface Signal, this vulnerability is very unlikely to be reachable from the internet. openCode is primarily a developer-centric tool used in internal or build environments, not a web service designed for public access. You should primarily focus your concern on internal systems where unauthorized users might have access to the component's interface.

What is the first step to address this risk?

The most important immediate step is to conduct an internal audit to locate all instances of openCode within your infrastructure. Once identified, determine which instances are business-critical and whether they are accessible to unauthorized users. After mapping your internal footprint, coordinate with your development teams to prioritize these instances for upcoming maintenance and remediation planning.