OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.
References
| Link | Resource |
|---|---|
| https://github.com/anomalyco/opencode/security/advisories/GHSA-vxw4-wv6m-9hhh | Vendor Advisory Exploit |
| https://github.com/anomalyco/opencode/security/advisories/GHSA-vxw4-wv6m-9hhh | Vendor Advisory Exploit |
Configurations
History
21 Jan 2026, 15:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/anomalyco/opencode/security/advisories/GHSA-vxw4-wv6m-9hhh - Vendor Advisory, Exploit | |
| CPE | cpe:2.3:a:anoma:opencode:*:*:*:*:*:-:*:* | |
| First Time |
Anoma
Anoma opencode |
13 Jan 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/anomalyco/opencode/security/advisories/GHSA-vxw4-wv6m-9hhh - |
12 Jan 2026, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-12 23:15
Updated : 2026-01-21 15:14
NVD link : CVE-2026-22812
Mitre link : CVE-2026-22812
CVE.ORG link : CVE-2026-22812
JSON object : View
Products Affected
anoma
- opencode
