datadog-security-labs · Crawled Sep 24, 2026
Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4)
2 IoCs
Read original article ↗
AI Summary
A remote code execution (RCE) vulnerability, tracked as GHSA-632h-h47v-g4x4, was discovered in OpenCode versions 1.14.30 through 1.18.21. The flaw exists in the /global/upgrade API endpoint, where a content-type confusion allows attackers to exploit a code injection vulnerability by submitting a malicious npm package via a cross-origin POST request. The attack can be triggered when a user visits a malicious webpage while running an unsecured OpenCode instance, leading to execution of preinstall scripts from the attacker-controlled package. The vulnerability was patched in OpenCode 1.18.22 by restricting the upgrade target to valid semantic versions and enforcing proper content-type validation.
AI-extracted · verify before operational use