Vulnerabilities

Summary — last 7 days

New vulnerabilities2,743▲ 32 vs. last week
Critical / high1,477▲ 367 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

14 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (9.1)0.34%—OpencodeAI9/22/20269/24/2026
Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload.
DeferredCritical (9.3)0.81%—OpencodeAI9/10/20269/11/2026
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
DeferredCritical (9.3)0.84%—Opencode StudioAI8/4/20269/16/2026
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate…
DeferredMedium (6.3)0.16%—Ai-sdk Harness OpencodeAIHarness AgentAIOpencodeAI7/20/20267/23/2026
The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.28, the tool relay authorizes requests from any process whose command line contains an allowed helper script path (`host-tool-mcp.mjs`). This allows untrusted code executing in the sandbox to invoke…
DeferredMedium (6.3)0.16%—Ai-sdk Harness-opencodeAIOpenai Codex-sdkAI7/20/20267/23/2026
The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command line interface. Prior to version 1.0.29, the tool relay authorizes requests from any process whose command line contains an allowed helper script path (the Codex CLI shim). This allows untrusted code…
AnalyzedHigh (8.1)0.27%—Opencode Ussd Gateway3/5/20266/17/2026
OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authenticated low-privileged attackers to gain to access to arbitrary SMS messages via a crafted company or tenant identifier parameter.
AnalyzedCritical (9.4)0.92%—Anoma Opencode1/12/20266/17/2026
OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web interface to prevent JavaScript execution via HTML injection. This means controlling the LLM response for a chat session…
AnalyzedHigh (8.8)17%—Anoma Opencode1/12/20266/17/2026
OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.
AnalyzedMedium (4.3)0.29%—Opencode Ussd Gateway11/26/20256/17/2026
Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs.
AnalyzedMedium (6.5)0.34%—Opencode Ussd Gateway11/26/20256/17/2026
Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user records and access sensitive information.
AnalyzedMedium (6.1)0.27%—Opencode Ussd Gateway11/26/20256/17/2026
A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload.
AnalyzedCritical (9.8)0.45%—Opencode Ussd Gateway11/26/20256/17/2026
OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint.
AnalyzedCritical (9.8)0.45%—Opencode Ussd Gateway11/26/20256/17/2026
OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByProvider function.
DeferredMedium (6.1)0.45%—Opencode Mobile Collect CallAI1/9/20256/17/2026
A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter at /occontrolpanel/index.php.