logo

Critical OpenCode Flaws Let Websites Hijack Your PC

ID: 377afd76-eb75-5ab1-ba8e-c9631a2ef1dd

STIX ID: report--377afd76-eb75-5ab1-ba8e-c9631a2ef1dd

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Two high-severity vulnerabilities in the OpenCode agent (CVE-2026-22813, CVE-2026-22812) allow remote code execution: a stored XSS in the web UI can be used to call the local OpenCode API, and the built-in HTTP server runs without authentication and with permissive CORS exposing endpoints that execute shell commands and read files; affected versions are prior to 1.0.216 and a patch is available in 1.0.216 — users should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.