Published September 24, 2026 · Added September 29, 2026

Cross-site OpenCode server upgrade request can install arbitrary packages

A high-severity (CVSS 7.5) advisory for the open source OpenCode AI coding agent says a malicious webpage can make the HTTP server started with `opencode serve` install an attacker-controlled package through npm, pnpm, or Bun and achieve remote code execution on a developer machine, while standalone CLI upgrades are unaffected. The advisory credits Datadog Security Labs research, lists affected npm versions from 1.14.30, and says version 1.18.22 fixes the flaws by restricting package sources and enforcing the endpoint's declared JSON contract.

A high-severity (CVSS 7.5) advisory for the open source OpenCode AI coding agent says a malicious webpage can make the HTTP server started with opencode serve install an attacker-controlled package through npm, pnpm, or Bun and achieve remote code execution on a developer machine, while standalone CLI upgrades are unaffected. The advisory credits Datadog Security Labs research, lists affected npm versions from 1.14.30, and says version 1.18.22 fixes the flaws by restricting package sources and enforcing the endpoint’s declared JSON contract.

Read the original story.

Source: Github