CVE-2026-22812

HIGH NUCLEI

OpenCode <1.0.216 - Command Injection

Title source: llm

Description

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.

Exploits (9)

github SCANNER 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/2026/OpenCode-CVE-2026-22812-RCE-poc.py
nomisec WORKING POC 30 stars
by rohmatariow · poc
https://github.com/rohmatariow/CVE-2026-22812-exploit
nomisec STUB 2 stars
by barrersoftware · poc
https://github.com/barrersoftware/opencode-secure
nomisec WORKING POC 1 stars
by 0xgh057r3c0n · poc
https://github.com/0xgh057r3c0n/CVE-2026-22812
nomisec WORKING POC 1 stars
by Udyz · poc
https://github.com/Udyz/CVE-2026-22812-Exp
nomisec WORKING POC
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-22812
nomisec WRITEUP
by HodgeLuke · poc
https://github.com/HodgeLuke/ai-agent-security-research
nomisec WORKING POC
by CayberMods · poc
https://github.com/CayberMods/CVE-2026-22812-POC
nomisec SCANNER
by mad12wader · poc
https://github.com/mad12wader/CVE-2026-22812

Nuclei Templates (1)

OpenCode < 1.0.216 - Unauthenticated Remote Code Execution
HIGHVERIFIEDby princechaddha
Shodan: http.html:"opencode"

Scores

CVSS v3 8.8
EPSS 0.0415
EPSS Percentile 88.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-306 CWE-749 CWE-942
Status published
Products (2)
anoma/opencode < 1.0.216
npm/opencode-ai 0 - 1.0.216npm
Published Jan 12, 2026
Tracked Since Feb 18, 2026