A significant security flaw has been identified in OpenCode, an open-source AI coding agent, that could permit harmful websites to execute unauthorized commands on a developer’s system.
Known as GHSA-632h-h47v-g4x4, this remote code execution vulnerability involves a content-type confusion in OpenCode’s /global/upgrade API. This flaw, combined with insecure handling of a potentially malicious upgrade target, was addressed by Anomaly in the update to OpenCode version 1.18.22.
OpenCode’s Integration and Security Concerns
Launched in June 2025, OpenCode has become a key tool in integrating language models into developer environments. Its popularity, with over 208,000 stars on GitHub and 16 million active monthly developers, underscores the critical nature of this security vulnerability.
The vulnerability primarily affects OpenCode’s browser interface, which operates through ‘opencode serve’ or ‘opencode web’. This interface listens on 127.0.0.1:4096 without default authentication, making it susceptible to unauthorized access.
Technical Details of the Vulnerability
According to Datadog Security Labs, the flaw affects versions 1.14.30 through 1.18.21 when installed using npm, pnpm, or Bun. The /global/upgrade endpoint can be manipulated to install a malicious package if an attacker supplies a URL to a remote tarball instead of a proper version target.
Attackers can exploit this by creating an archive with a harmful package.json preinstall script, running commands with the privileges of the OpenCode process. Although the server binds to localhost, a crafted webpage could trick a user’s browser into interacting with the local API using a method not blocked by CORS.
Preventive Measures and Security Recommendations
To mitigate this risk, developers using the affected versions should upgrade promptly to OpenCode 1.18.22 or later. This version enhances security by validating upgrade targets and rejecting inappropriate submissions, like text/plain content types.
Developers are also advised to configure OPENCODE_SERVER_PASSWORD for added security when using the web interface and to monitor for unusual package-manager activity as potential signs of compromise.
While password protection can reduce exposure, it is not a substitute for the critical patching provided in the latest update. Cached credentials in the browser may still be leveraged for malicious requests, emphasizing the importance of comprehensive security practices.
