hey maintainer here we've done a poor job handling these security reports, usage has grown rapidly and we're overwhelmed with issues we're meeting with some people this week to advise us on how to handle this better, get a bug bounty program funded and have some audits done
Why not just ask Claude to fix the security issues and make sure they don't happen again?
Unauthenticated remote code execution in OpenCode
21–30 of 155 posts
Re: Unauthenticated remote code execution in OpenCode
#22Huh, I thought opencode was a volunteer project but it looks like it's a business with major backing from major players. Was opencode always set up like this? I could have sworn there was some project with a better governance model, guess not.
Re: Unauthenticated remote code execution in OpenCode
#23Having said that, there is definitely a need for open platform to utilize multiple vendors and models. I just don’t think the big three (Anthropic, OAI and Google) will cede that control over with so much money on the line.
Re: Unauthenticated remote code execution in OpenCode
#24So did they fix it silently, without responding to the researcher, or they fixed the silent part where now user is made a aware that a website is trying to execute code on their machine.
Re: Unauthenticated remote code execution in OpenCode
#25> Silent fix So did they fix it silently, without responding to the researcher, or they fixed the silent part where now user is made a aware that a website is trying to execute code on their machine.
Re: Unauthenticated remote code execution in OpenCode
#26Maybe I'm using GitHub code search wrongly, but it appears this was just never part of even a pull request - the practice of just having someone pushing to `dev` (default branch) which then will be tagged should perhaps also be revisited.
(Several more commits under `wip: bash` and `feat: bash commands`)
https://github.com/anomalyco/opencode/commit/7505fa61b9caa17...
https://github.com/anomalyco/opencode/commit/93b71477e665600...
Re: Unauthenticated remote code execution in OpenCode
#27I'd be curious to know what features need opencode.ai to be an allowed origin for the local server.
Re: Unauthenticated remote code execution in OpenCode
#28hey maintainer here we've done a poor job handling these security reports, usage has grown rapidly and we're overwhelmed with issues we're meeting with some people this week to advise us on how to handle this better, get a bug bounty program funded and have some audits done
Re: Unauthenticated remote code execution in OpenCode
#29hey maintainer here we've done a poor job handling these security reports, usage has grown rapidly and we're overwhelmed with issues we're meeting with some people this week to advise us on how to handle this better, get a bug bounty program funded and have some audits done