Vulnerability
Published 2026-09-24
Verified 2026-09-25

OpenCode GHSA-632h-h47v-g4x4 (CVSS 7.5): cross-site /global/upgrade → arbitrary npm package RCE via opencode serve

Datadog Security Labs (published 24 September 2026; GHSA published 24 Sep 2026 13:36 UTC) documents GHSA-632h-h47v-g4x4 in Anomaly OpenCode, an open-source AI coding agent (≥200k GitHub stars / ~16M monthly users per vendor site). A content-type confusion on the /global/upgrade HTTP API made an underlying code-injection path reachable cross-origin: a malicious webpage can submit a top-level HTML form POST that installs an attacker-controlled npm/pnpm/Bun package tarball (lifecycle scripts → RCE) when the victim is running opencode serve (or opencode web) with an npm-managed install. Default serve has no auth; HTTP Basic helps only until the browser caches credentials. Browser CORS / Local Network Access prompts do not block top-level navigations. Affected: OpenCode ≥1.14.30 through 1.18.21 (npm/pnpm/Bun installs). Not this path: curl/Homebrew/Chocolatey/Scoop installs; users not running the HTTP server. Fixed in 1.18.22 (Anomaly patched 24 Aug 2026; publication delayed ~1 month). Anomaly declined a CVE. GHSA CVSS 3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H (High; score 7.5). Primary: Datadog Security Labs; vendor: GitHub GHSA.

Product
Anomaly OpenCode AI coding agent (opencode serve / opencode web HTTP server; npm/pnpm/Bun installs)
Versions
Affected ≥1.14.30 through 1.18.21 (npm/pnpm/Bun). Fixed 1.18.22. curl/Homebrew/Chocolatey/Scoop installs and non-serve CLI use not on this cross-site path.
CVSS
(CVSS 3.1 High; GHSA vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H — Anomaly declined CVE)
Exploited in Australia?
unknown
Patch to
Upgrade OpenCode to 1.18.22+; do not leave opencode serve exposed on untrusted networks; prefer non-npm install channels if you must stay on older builds; treat unexpected localhost:4096 /global/upgrade navigations as hostile

Primary: Datadog Security Labs — OpenCode upgrade RCE (24 Sep 2026) · Vendor: GitHub GHSA-632h-h47v-g4x4 — anomalyco/opencode (24 Sep 2026) · Datadog — how OpenCode fixed /global/upgrade

tech ai cloud