important · Edge — Developer tooling
A malicious webpage can make a local OpenCode server install an attacker package and execute its lifecycle script.
Affects
OpenCode, a cross-platform AI coding agent with an optional local HTTP web interface.
The browser submits cross-origin text/plain JSON to the loopback upgrade endpoint, which accepts the attacker's tarball as the package target.
Detail and 3 sources
The upstream advisory publishes the complete proof of concept, Datadog demonstrated it against version 1.18.21, and the merged fix limits targets to semantic versions while restoring typed JSON decoding.
Sources
ResearchDiscovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4) | Datadog Security LabsCode / PoCCross-site OpenCode server upgrade request can install arbitrary packages for npm-based installations · Advisory · anomalyco/opencode · GitHubCode / PoCfix(opencode): normalize upgrade endpoint by thdxr · Pull Request #44686 · anomalyco/opencode · GitHub