/Vulnerability Library

OpenCode < 1.0.216 - Unauthenticated Remote Code Execution

CVE-2026-22812
Verified

Description

OpenCode versions prior to 1.0.216 contain an unauthenticated remote code execution vulnerability. The application exposes session and shell execution endpoints without proper authentication, allowing remote attackers to create sessions and execute arbitrary shell commands on the underlying server.

Severity

High

CVSS Score

8.8

Exploit Probability

17%

Affected Product

opencode

Published Date

January 27, 2026

Template Author

princechaddha

CVE-2026-22812.yaml
8.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-22812
CWE ID:
cwe-306

References

https://github.com/rohmatariow/CVE-2026-22812-exploithttps://nvd.nist.gov/vuln/detail/CVE-2026-22812

Remediation Steps

Upgrade OpenCode to version 1.0.216 or later.