Intel

AIKIDO-2026-10207

oh-my-opencode is vulnerable to Improper Authorization

Improper Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 21, 2026

72

High Risk

This Affects:

JSoh-my-opencode
2.14.1 - 3.3.2
Fixed in 3.4.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper authorization that can lead to unintended command execution. In Prometheus (plan-builder) mode, the permission configuration for bash commands is bypassed, allowing commands to execute without the expected user confirmation. Since this mode is intended to be read-only, this behavior can allow unauthorized command execution.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

oh-my-opencode is vulnerable to Improper Authorization in versions 2.14.1 - 3.3.2.

How to fix this

Upgrade the oh-my-opencode library to the patch version.