CVE-2026-22812
high · 8.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.
8.8
CVSS
16.8%
EPSS (exploit prob.)
97th
EPSS percentile
2026-01-12
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-306CWE-749CWE-942
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| anoma | opencode | < 1.0.216 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-22812