GHSA-c83v-7274-4vgp
CRITICALCVE-2026-22813A malicious website can abuse the server URL override feature of the OpenCode web UI to achieve cross-site scripting on http://localhost:4096. From there, it is possible to run arbitrary commands on the local system using the /pty/ endpoints provided by the OpenCode API.
- Affected
- < 1.1.10
- Fixed in
- 1.1.10
- Weakness
- CWE-79
- Published
- 2026-01-13
- Source
- github