OpenCode: a cross-site request to the upgrade endpoint could install arbitrary packages
Datadog Security Labs (24 Sep 2026) detailed how a malicious web page could reach a local OpenCode server and trigger an attacker-chosen package install. Fixed in 1.18.22.
What is this?
On 24 September 2026, Datadog Security Labs (finding credited to Christophe Tafani-Dereeper) and the OpenCode maintainers published details of a vulnerability in OpenCode, an open-source AI coding agent that can expose a local HTTP server through opencode serve or opencode web. The GitHub advisory (GHSA-632h-h47v-g4x4, rated High, CVSS 7.5, no CVE assigned) describes a cross-site request that can make the server install attacker-chosen packages, leading to code execution on the developer’s machine.
The timeline is a textbook coordinated disclosure: reported on 11 August 2026, fixed and released as version 1.18.22 on 24 August 2026, and made public after a one-month embargo on 24 September.
How it works
Two weaknesses combine. First, the server’s upgrade endpoint accepted an arbitrary URL as the thing to install, instead of restricting the request to a version number. Second, the server parsed request bodies as JSON without checking that the Content-Type header actually said JSON. A web page can make a browser send a cross-site form submission with a plain-text content type without triggering the usual preflight protection, and that body can still be valid JSON.
Put together, a page visited by a developer who has a local OpenCode server running could make the browser ask that server to install a package from an attacker-controlled location. For installations managed through npm, pnpm or Bun, package lifecycle scripts then run during installation. According to the advisory, the attack can also work when HTTP Basic authentication is enabled if the browser has cached the credentials. Installations done through curl, Homebrew, Chocolatey or Scoop are not exposed to this particular installation vector.
Why it matters
The attacker needs no foothold on the machine: the victim only has to open a web page while a local agent server is listening. This is the same class of problem seen earlier in 2026 with browser-reachable local AI gateways: “localhost” is not a security boundary when any web page can make requests to it. Coding agents also tend to run with the developer’s credentials, repositories and shell access, so code executed through the agent’s own update path inherits all of it.
Defenses
- Upgrade to OpenCode 1.18.22 or later. No workaround is documented in the advisory beyond upgrading.
- Require password authentication for
opencode serveandopencode web, and do not expose them beyond the local machine unless necessary. - Check how OpenCode was installed (for example with
ls -l "$(command -v opencode)"); the package-install vector concerns npm, pnpm and Bun installations. - Treat local agent servers as internet-facing services: enforce Origin allowlisting, reject non-JSON content types on JSON endpoints, and avoid endpoints that accept arbitrary install targets.
- Stop local agent servers when not in use, and avoid browsing untrusted sites in the same session.
Status
| Aspect | Detail |
|---|---|
| Primary source | Datadog Security Labs, 24 September 2026 |
| Advisory | GHSA-632h-h47v-g4x4 (High, CVSS 7.5, no CVE assigned) |
| Reported / fixed / public | 11 Aug 2026 / 24 Aug 2026 (1.18.22) / 24 Sep 2026 |
| Affected | OpenCode from 1.14.30 (advisory lists up to 1.18.16; Datadog lists up to 1.18.21) |
| Patched | 1.18.22 and later |