CVE-2026-22812

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.

Scoring

Severity
HIGH
CVSS base score
8.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS probability
16.77%
CWE
CWE-306, CWE-749, CWE-942
Published
2026-01-12
Last modified
2026-03-12

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs