CVE-2026-22812
HIGH NUCLEIOpenCode <1.0.216 - Command Injection
Title source: llmDescription
OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.
Exploits (9)
github
SCANNER
40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/2026/OpenCode-CVE-2026-22812-RCE-poc.py
nomisec
WORKING POC
30 stars
by rohmatariow · poc
https://github.com/rohmatariow/CVE-2026-22812-exploit
Nuclei Templates (1)
OpenCode < 1.0.216 - Unauthenticated Remote Code Execution
HIGHVERIFIEDby princechaddha
Shodan:
http.html:"opencode"
Scores
CVSS v3
8.8
EPSS
0.0415
EPSS Percentile
88.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-306
CWE-749
CWE-942
Status
published
Products (2)
anoma/opencode
< 1.0.216
npm/opencode-ai
0 - 1.0.216npm
Published
Jan 12, 2026
Tracked Since
Feb 18, 2026