Known CVE
OpenCode < 1.0.216 - Unauthenticated Remote Code Execution
OpenCode versions prior to 1.0.216 contain an unauthenticated remote code execution vulnerability. The application exposes session and shell execution endpoints without proper authentication, allowing remote attackers to create sessions and execute arbitrary shell commands on the underlying server.
CVE-2026-22812
High2026CVSS 8.8CWE-306
cve2026 · opencode · rce · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website