Knowns versions prior to 0.31.0 improperly validate a client-controlled directory request header processed by the OpenCode proxy functionality. An attacker can supply an arbitrary directory path, causing file operations to be performed outside the intended project root on the host system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains one standalone Python 3 PoC harness, an MIT license, and a README. CVE-2026-88899.py does not exploit a live product: it starts a mock OpenCode daemon and a simulated Knowns reverse proxy, records forwarded headers/query strings, and runs five deterministic tests. The tests model a fail-open condition in which x-opencode-directory is overwritten only when absent and directory is injected only for GET /session when absent. They demonstrate header-based workspace selection, directory query injection on GET and POST requests, and a fail-closed simulated remediation that strips and overwrites both values with the active project root. The README claims that a real exposed Knowns proxy could allow an attacker to redirect an OpenCode AI agent to arbitrary host directories, with possible file access, session leakage, and agent-mediated command execution. Those higher-impact actions are illustrative documentation; no real Knowns/OpenCode target, credentials, external listener, agent tooling, reverse shell, or filesystem modification is invoked by the included code.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.