PT-2026-61722 · Npm · @Ai-Sdk/Harness-Opencode

CVE-2026-64650

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

6.3

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions @ai-sdk/harness-opencode versions prior to 1.0.29
Description The tool relay authorizes requests from any process whose command line contains an allowed helper script path. This allows untrusted code executing in the sandbox to invoke arbitrary host-exposed tools, such as secret lookups, deployment operations, and cloud API calls, without a model-authorized tool-call event. Exploitation requires a Linux environment, an active harness session with host-provided tools, and untrusted code executing in the sandbox, such as a malicious dependency, build script, or lifecycle hook. Real-world incidents of this issue being exploited have been reported.
Recommendations Update to version 1.0.29 or later. Do not run the Codex harness on untrusted repositories or with untrusted dependencies. Limit host-exposed tools to non-sensitive operations when working with untrusted code.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64650

Affected Products

@Ai-Sdk/Harness-Opencode