Skip to finding
important · Edge — Developer tooling

A malicious webpage can make a local OpenCode server install an attacker package and execute its lifecycle script.

Affects

OpenCode, a cross-platform AI coding agent with an optional local HTTP web interface.

The browser submits cross-origin text/plain JSON to the loopback upgrade endpoint, which accepts the attacker's tarball as the package target.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 26, 2026