OpenCode AI Coding Agent Flaw Lets Malicious Websites Execute Code on Developer Machines

A critical attack path in OpenCode, an open-source AI coding agent, could let a malicious website execute commands on a developer’s computer. Tracked as GHSA-632h-h47v-g4x4, the remote code execution vulnerability combines content-type confusion in OpenCode’s /global/upgrade API with unsafe handling of an attacker-controlled upgrade target. Anomaly fixed the issue in OpenCode 1.18.22. OpenCode launched in June 2025 […]

This article has been indexed from Cyber Security News

Read the original article: