ZombAI Exploit with OpenHands: Prompt Injection To Remote Code Execution
Summary
OpenHands, a popular AI agent from All Hands AI that can now run as a cloud service, is vulnerable to prompt injection (tricking an AI by hiding instructions in its input) when processing untrusted data like content from websites. This vulnerability allows attackers to hijack the system and compromise its confidentiality, integrity, and availability, potentially leading to full system compromise.
Classification
Affected Vendors
Related Issues
Original source: https://embracethered.com/blog/posts/2025/openhands-remote-code-execution-zombai/
First tracked: February 12, 2026 at 02:20 PM
Classified by LLM (prompt v3) · confidence: 85%