PT-2026-61723 · Npm · @Ai-Sdk/Harness-Opencode
CVE-2026-64651
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v4.0
6.3
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
@ai-sdk/harness-opencode versions prior to 1.0.28
Description
The tool connects HarnessAgent to OpenCode via a sandboxed bridge. The tool relay authorizes requests from any process whose command line contains the allowed helper script path
host-tool-mcp.mjs. This allows untrusted code executing in the sandbox to invoke arbitrary host-exposed tools, such as secret lookups, deployment operations, and cloud API calls, without a model-authorized tool-call event. Exploitation requires a Linux environment, an active harness session with host-provided tools, and untrusted code executing in the sandbox, such as a malicious dependency, build script, or lifecycle hook.Recommendations
Update to version 1.0.28 or later.
Do not run the OpenCode harness on untrusted repositories or with untrusted dependencies.
Limit host-exposed tools to non-sensitive operations when working with untrusted code.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Ai-Sdk/Harness-Opencode