CVE-2026-22812HIGH 8.8EPSS p96.7%
CVE-2026-22812CVE-2026-22812
Description
OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 16.96% probability of exploitation · percentile 96.7% · 2026-06-18T12:00:27Z |
| Published | 2026-01-12 |
| Last modified | 2026-01-21 |
Underlying weaknesses· 3
References
3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Missing Authentication for Critical Functioncwe-306 | 0% | live |
| Weakness | Exposed Dangerous Method or Functioncwe-749 | 0% | live |
| Weakness | Permissive Cross-domain Security Policy with Untrusted Domainscwe-942 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.