Skip to finding
important · RCE

A malicious webpage can make an npm-installed OpenCode server install an attacker package and run its lifecycle script.

Affects

OpenCode, a cross-platform local coding-agent server and web interface.

A top-level text/plain form navigation avoids a CORS preflight and supplies a remote package URL to the local upgrade endpoint.

Detail and 2 sources

npm, pnpm, or Bun then installs the package and executes its lifecycle script as the OpenCode user; cached Basic credentials can preserve the path even when the server is password protected.

The corrected release rejects the reproduced request with HTTP 415 and limits upgrade targets to semantic versions.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026