OpenCode < 1.0.216 - Unauthenticated Remote Code Execution
CVE-2026-22812
Verified
Description
OpenCode versions prior to 1.0.216 contain an unauthenticated remote code execution vulnerability. The application exposes session and shell execution endpoints without proper authentication, allowing remote attackers to create sessions and execute arbitrary shell commands on the underlying server.
Severity
High
CVSS Score
8.8
Exploit Probability
17%
Affected Product
opencode
Published Date
January 27, 2026
Template Author
princechaddha
CVE-2026-22812.yaml
8.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-22812
CWE ID:
cwe-306
Remediation Steps
Upgrade OpenCode to version 1.0.216 or later.