Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. opencode-ai
  4. ›
  5. CVE-2026-22812

CVE-2026-22812: OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution

January 13, 2026

OpenCode automatically starts an unauthenticated HTTP server that allows any local process—or any website via permissive CORS—to execute arbitrary shell commands with the user’s privileges.

References

  • github.com/advisories/GHSA-vxw4-wv6m-9hhh
  • github.com/anomalyco/opencode
  • github.com/anomalyco/opencode/commit/7d2d87fa2c44e32314015980bb4e59a9386e858c
  • github.com/anomalyco/opencode/security/advisories/GHSA-vxw4-wv6m-9hhh
  • nvd.nist.gov/vuln/detail/CVE-2026-22812

Code Behaviors & Features

Detect and mitigate CVE-2026-22812 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.0.216

Fixed versions

  • 1.0.216

Solution

Upgrade to version 1.0.216 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-306: Missing Authentication for Critical Function
  • CWE-749: Exposed Dangerous Method or Function
  • CWE-942: Permissive Cross-domain Policy with Untrusted Domains

Source file

npm/opencode-ai/CVE-2026-22812.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 20 Jan 2026 12:17:32 +0000.