Datadog Security Labs disclosed GHSA-632h-h47v-g4x4, a remote-code-execution flaw in the local web/API server of the OpenCode AI coding agent. OpenCode versions 1.14.30 through 1.18.21 accepted attacker-controlled upgrade targets that npm, pnpm, or Bun could resolve as remote package tarballs; package lifecycle scripts could then execute on the developer’s machine. A separate content-type validation weakness allowed a malicious website to send a cross-origin top-level text/plain form request containing JSON to the localhost upgrade endpoint, bypassing controls that would ordinarily prevent cross-origin JavaScript requests.
Exploitation requires a vulnerable OpenCode installation obtained through npm, pnpm, or Bun that is running opencode serve or opencode web without password authentication, or where the browser has cached authentication credentials. Anomaly corrected the package-target and request-content-type validation issues in OpenCode 1.18.22; organizations should upgrade affected developer endpoints and avoid exposing unauthenticated local OpenCode web services.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Anomaly published GHSA-632h-h47v-g4x4 after a one-month coordinated-disclosure delay requested following the patch release. The advisory describes remote code execution via the local OpenCode upgrade endpoint in versions 1.14.30 through 1.18.21.
Anomaly fixed the vulnerability in PR #44686 and commit c6e76e9, releasing OpenCode 1.18.22. The release restricts upgrade targets to valid semantic versions and enforces request content types, blocking the text/plain cross-origin exploit path.
Datadog Security Labs reported the GHSA-632h-h47v-g4x4 vulnerability to Anomaly through GitHub Security Advisories.
OpenCode 1.14.30, the first release affected by the upgrade-endpoint remote code execution flaw, was released.
OpenCode PR #24853 introduced the vulnerable upgrade code path, allowing arbitrary upgrade targets to reach package-manager installation commands.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcesecuritylabs.datadoghq.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.