OpenCode AI coding agent hit by critical unauthenticated RCE vulnerability
1–3 of 3 posts
Re: OpenCode AI coding agent hit by critical unauthenticated RCE vulnerability
#2Probably nothing.
Re: OpenCode AI coding agent hit by critical unauthenticated RCE vulnerability
#3Probably nothing.
Probably nothing based on what? I have reproduced the finding locally...
Any website can trivially run arbitrary code as the current user if OpenCode is installed; that's CVSS ~10.