CVE-2026-22812 describes an unauthenticated remote code execution vulnerability in OpenCode, an open-source AI coding agent, affecting versions prior to 1.0.216. The flaw stems from an automatically started, unauthenticated HTTP server that allows local processes or websites with permissive CORS to execute arbitrary shell commands with user privileges. This high-severity vulnerability (CVSS 8.8) has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, a Nuclei template for exploitation exists, and the vulnerability has garnered significant community discussion, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.216CPE matchmatch criteria | cpe:2.3:a:anoma:opencode:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Anoma OpenCode Command Injection (CVE-2026-22812)
Mar 12, 2026Anoma OpenCode Command Injection (CVE-2026-22812)
Mar 12, 2026Anoma OpenCode Command Injection (CVE-2026-22812)
Mar 12, 2026Anoma OpenCode Command Injection (CVE-2026-22812)
Mar 12, 2026Anoma OpenCode Command Injection (CVE-2026-22812)
Mar 12, 2026OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution
Jan 13, 2026