OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.
References
| Link | Resource |
|---|---|
| https://github.com/anomalyco/opencode/security/advisories/GHSA-vxw4-wv6m-9hhh | Vendor Advisory Exploit |
| https://github.com/anomalyco/opencode/security/advisories/GHSA-vxw4-wv6m-9hhh | Vendor Advisory Exploit |
Configurations
History
No history.
Information
Published : 2026-01-12 23:15
Updated : 2026-01-21 15:14
NVD link : CVE-2026-22812
Mitre link : CVE-2026-22812
CVE.ORG link : CVE-2026-22812
JSON object : View
Products Affected
anoma
- opencode
