PT-2026-2316 · Opencode · Opencode
Albertspedersen
·
Published
2026-01-12
·
Updated
2026-03-05
·
CVE-2026-22813
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
OpenCode versions prior to 1.1.10
Description
The software is an open source AI coding agent. The markdown renderer used for responses from large language models inserts arbitrary HTML into the Document Object Model (DOM) without sanitization. There is no Content Security Policy (CSP) implemented on the web interface to prevent JavaScript execution through HTML injection. This allows an attacker to control the large language model response for a chat session and achieve JavaScript execution on the 'http://localhost:4096' origin.
Recommendations
Update to version 1.1.10 or later.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencode