Intel

AIKIDO-2026-10216

opencode-antigravity-auth is vulnerable to Incorrect Default Permissions

Incorrect Default Permissions Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 21, 2026

29

Low Risk

This Affects:

JSopencode-antigravity-auth
1.1.0 - 1.4.6
Fixed in 1.5.0
Are you affected? Scan for Free

TL;DR

Affected versions of opencode-antigravity-auth store credential files with overly permissive file system permissions, allowing other local users or processes on the same system to read or modify sensitive authentication data. This could result in unauthorized access to stored tokens and credentials used for OAuth authentication against Antigravity. The issue is fixed by explicitly setting secure file permissions (0600) for credential storage to ensure only the owning user can read or write these files, reducing the risk of local credential disclosure.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

opencode-antigravity-auth is vulnerable to Incorrect Default Permissions in versions 1.1.0 - 1.4.6.

How to fix this

Upgrade the opencode-antigravity-auth library to the patch version.