PoC Index

CVE-2026-22812

HIGH 8.8EPSS 17.3%

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
17.33% chance of exploitation in the next 30 days, 97th percentile
Nuclei
high · CWE-306
Published
2026-01-12
Updated
2026-01-13

Proof-of-concept exploits (8)

Nuclei templates (1)

References

Related