Anoma
Anoma's modest vulnerability footprint centers on its OpenCode product and reflects characteristic weaknesses in web application security, including exposed dangerous methods, cross-site scripting, missing authentication for critical functions, and permissive cross-domain policies. Current severity, exploitation, and exposure counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Anoma over time
Products(1 total)
Top CVEs
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22812HIGH OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permiss | Jan 12, 2026 | 8.8 | 55 | NO | YES |
CVE-2026-22813MEDIUM OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a | Jan 12, 2026 | 6.1 | 25 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (2 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Anoma.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Anoma — matched by CVE ID, not by vendor name.