← Back to browse · API

CVE-2026-22812

Severity
HIGH
CVSS
8.8
EPSS
0.16973
Risk score
41.14
CISA KEV
No
PoC
Yes
Published
2026-01-12
Modified
2026-01-13
First seen
2026-08-07
Aliases
EUVD-2026-2092, GHSA-VXW4-WV6M-9HHH
Products
anomalyco:opencode < 1.0.216
Sources
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-22812
euvd EUVD-2026-2092

Description

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.

References