<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T01:10:10.556114+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-22813</id>
    <title>CVE-2026-22813 — Malicious website can execute commands on the local system through XSS in the OpenCode web UI</title>
    <updated>2026-10-05T01:10:10.557727+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> anomalyco opencode</p>
<p>OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web interface to prevent JavaScript execution via HTML injection. This means controlling the LLM response for a chat session gets JavaScript execution on the http://localhost:4096 origin. This vulnerability is fixed in 1.1.10.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-22813"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c83v-7274-4vgp</id>
    <title>GHSA-c83v-7274-4vgp — Malicious website can execute commands on the local system through XSS in the OpenCode web UI</title>
    <updated>2026-10-05T01:10:10.557777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: opencode-ai</p>
<p>### Summary
A malicious website can abuse the server URL override feature of the OpenCode web UI to achieve cross-site scripting on `http://localhost:4096`. From there, it is possible to run arbitrary commands on the local system using the `/pty/` endpoints provided by the OpenCode API.</p>
<p>### Code execution via OpenCode API</p>
<p>- The OpenCode API has `/pty/` endpoints that allow spawning arbitrary processes on the local machine.
- When you run `opencode` in your terminal, OpenCode automatically starts an HTTP server on `localhost:4096` that exposes the API along with a web interface.
- JavaScript can make arbitrary same-origin `fetch()` requests to the `/pty/` API endpoints. Therefore, JavaScript execution on `http://localhost:4096` gets you code execution on local the machine.</p>
<p>### JavaScript execution on localhost:4096</p>
<p>The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web interface to prevent JavaScript execution via HTML injection.</p>
<p>This means controlling the LLM response for a chat session gets you JavaScript execution on the `http://localhost:4096` origin. This alone would not be enough for a 1-click exploit, but there's functionality in `packages/app/src/app.tsx` to allow specifying a custom server URL in a `?url=...` parameter:</p>
<p>```javascript
// packages/app/src/app.tsx
const defaultServerUrl = iife(() =&gt; {
  const param = new URLSearchParams(document.location.search).get(…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c83v-7274-4vgp"/>
  </entry>
</feed>
