Логотип exploitDog
bind:CVE-2026-22812
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-22812

Количество 2

Количество 2

nvd логотип

CVE-2026-22812

7 дней назад

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-vxw4-wv6m-9hhh

6 дней назад

OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-22812

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.

CVSS3: 8.8
0%
Низкий
7 дней назад
github логотип
GHSA-vxw4-wv6m-9hhh

OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution

CVSS3: 8.8
0%
Низкий
6 дней назад

Уязвимостей на страницу