Critical OpenCode Flaws Let Websites Hijack Your PC
ID: 377afd76-eb75-5ab1-ba8e-c9631a2ef1dd
STIX ID: report--377afd76-eb75-5ab1-ba8e-c9631a2ef1dd
Feed Name: securityonline.info
Threat Score
Two high-severity vulnerabilities in the OpenCode agent (CVE-2026-22813, CVE-2026-22812) allow remote code execution: a stored XSS in the web UI can be used to call the local OpenCode API, and the built-in HTTP server runs without authentication and with permissive CORS exposing endpoints that execute shell commands and read files; affected versions are prior to 1.0.216 and a patch is available in 1.0.216 — users should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
