opencode-ai is vulnerable to Missing Authentication
88
High Risk
OpenCode's HTTP server starts automatically without authentication middleware and with permissive CORS (Access-Control-Allow-Origin: *). Any local process—or a malicious website via cross-origin requests—can call endpoints such as POST /session/:id/shell, POST /pty, and GET /file/content to run arbitrary shell commands and read files under the user's privileges. The fix authenticates the HTTP server before accepting those requests.
You are affected if you are using a version that falls within the vulnerable range.
opencode-ai is vulnerable to Missing Authentication in versions 0.0.1 - 1.0.215.
Upgrade the opencode-ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.