OpenCode AI Coding Agent Flaw Lets Malicious Websites Execute Code
Key Takeaways A critical vulnerability in the OpenCode AI coding agent allowed malicious websites to execute arbitrary code on a user’s system. The flaw affected OpenCode versions 1.14.30...
Key Takeaways
- A critical vulnerability in the OpenCode AI coding agent allowed malicious websites to execute arbitrary code on a user’s system.
- The flaw affected OpenCode versions 1.14.30 through 1.18.21, specifically installations via npm, pnpm, or Bun running in ‘serve’ or ‘web’ modes without adequate password protection or with cached credentials.
- Exploitation required a user with a vulnerable setup to simply visit a specially crafted web page while their OpenCode server was active.
- Datadog researchers discovered and privately reported the issue on August 11, leading to a patch released on August 24.
- Users are strongly advised to upgrade to OpenCode version 1.18.22 or newer immediately to mitigate the risk.
Critical Flaw in OpenCode AI Agent Poses Remote Code Execution Risk
A significant security vulnerability has been identified in the OpenCode AI coding agent, enabling remote code execution (RCE) through crafted web pages. The flaw, affecting versions 1.14.30 to 1.18.21, could be exploited if a user with a vulnerable OpenCode server visited a malicious website.
Table Of Content
Vulnerability Details and Exploitation Conditions
The vulnerability specifically impacted OpenCode instances installed via npm, pnpm, or Bun, particularly when operating in ‘serve’ or ‘web’ modes. Systems were exposed if they lacked password protection or if valid basic-authentication credentials were cached within the user’s browser. Under these conditions, a simple visit to a specially designed webpage was sufficient for an attacker to execute arbitrary code on the victim’s system.
Datadog security researchers, who discovered the vulnerability, provided an exploitation flow diagram illustrating the attack vector. The core issue stemmed from insufficient validation of upgrade targets and improper handling of certain content types.
Impact and Affected Installations
Public data from npm, highlighted by Datadog, indicates a substantial number of potentially vulnerable installations. Between September 17 and 23, 2026, 82 vulnerable OpenCode releases accumulated over 647,000 downloads, representing 38.9% of all OpenCode downloads during that period. It is important to note that these figures reflect downloads and not necessarily unique active installations, nor do they specify how many users had the web service enabled, a prerequisite for exploitation.
Patch and Mitigation Efforts
The vulnerability’s code path was introduced on April 29 with the release of version 1.14.30. Datadog privately reported their findings on August 11, leading to a patch released by Anomaly on August 24. This update, included in OpenCode 1.18.22, implements several defense-in-depth measures. It now validates the upgrade target as a semantic version, thereby preventing the use of arbitrary package URLs. Additionally, it replaces the raw handler with a content-aware handler that rejects text/plain submissions, directly addressing the exploitation vector. For instance, OpenCode 1.18.22 now responds with an HTTP 415 “Unsupported Media Type” for the specific malicious request demonstrated by researchers. No CVE was requested for this vulnerability; therefore, defenders should monitor the GitHub advisory identifier for updates.
What You Should Do
- Upgrade Immediately: Update your OpenCode installation to version 1.18.22 or later without delay.
- Restart Processes: Ensure all active OpenCode processes are restarted after the upgrade to apply the patch effectively.
- Verify Installation: Confirm your installed version and the installation method (npm, pnpm, or Bun) to ensure the update was successful.
- Set Password Protection: Always set the
OPENCODE_SERVER_PASSWORDenvironment variable when using the OpenCode web interface. While password protection reduces exposure, it does not replace patching, as cached browser credentials could still facilitate attacks. - Limit Exposure: Avoid exposing the OpenCode service beyond
localhostto minimize potential attack surface. - Monitor for Anomalies: Be vigilant for unusual package-manager activity, unexpected lifecycle-script executions, or outbound downloads, as these could indicate a potential compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.