CVE-2026-22813

MEDIUM

OpenCode < 1.1.10 - Stored Cross-Site Scripting via Markdown Renderer

Title source: llm
STIX 2.1

Description

OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web interface to prevent JavaScript execution via HTML injection. This means controlling the LLM response for a chat session gets JavaScript execution on the http://localhost:4096 origin. This vulnerability is fixed in 1.1.10.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0004
EPSS Percentile 13.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
anoma/opencode < 1.1.10
npm/opencode-ai 0 - 1.1.10npm
Published Jan 12, 2026
Tracked Since Feb 18, 2026