PT-2026-61722 · Npm · @Ai-Sdk/Harness-Opencode
CVE-2026-64650
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v4.0
6.3
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
@ai-sdk/harness-opencode versions prior to 1.0.29
Description
The tool relay authorizes requests from any process whose command line contains an allowed helper script path. This allows untrusted code executing in the sandbox to invoke arbitrary host-exposed tools, such as secret lookups, deployment operations, and cloud API calls, without a model-authorized tool-call event. Exploitation requires a Linux environment, an active harness session with host-provided tools, and untrusted code executing in the sandbox, such as a malicious dependency, build script, or lifecycle hook. Real-world incidents of this issue being exploited have been reported.
Recommendations
Update to version 1.0.29 or later.
Do not run the Codex harness on untrusted repositories or with untrusted dependencies.
Limit host-exposed tools to non-sensitive operations when working with untrusted code.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Ai-Sdk/Harness-Opencode