Daily Editions
The update was the door — OpenCode's own upgrade endpoint installed the attacker's package, and the CRA limb that reaches it is not live until 2027
On 24 September 2026 Datadog Security Labs disclosed GHSA-632h-h47v-g4x4: a cross-site request to the OpenCode agent's local /global/upgrade endpoint could install an attacker-chosen package, because the endpoint parsed the body as JSON without checking Content-Type — so a form with enctype text/plain reached it — and then passed the target into npm install, where npm reads a target as a specifier that may be a URL to a tarball whose preinstall script runs. 82 releases were affected, 1.14.30 through 1.18.21, patched in 1.18.22 on 24 August. The obvious reading is a patch-and-move-on CVE, and the correction is propagation: in the week of 17-23 September, a month after the fix, 647,000 downloads — 38.9% of the week's total — were still vulnerable versions, though a download is not a machine and no source gives a unique-installation count. The regulatory shape is a gap rather than a duty: the Cyber Resilience Act's Article 14 reporting obligation has applied since 11 September 2026 but triggers only on actively exploited vulnerabilities, and nobody claims exploitation here, while the limb that speaks to the defect — Annex I, Part I, point (2), which requires products to limit attack surfaces including external interfaces and to make vulnerabilities addressable through security updates — does not apply until 11 December 2027. Article 13(9) keeps each update available for ten years; nothing live keeps it installed. The practitioner moves are therefore local: inventory listeners with ss -ltnp rather than grepping for one tool, treat localhost as a public origin wherever an agent serves without a password, put opencode-ai >= 1.18.22 in the dev-environment baseline rather than only the production SBOM, and add "does it open a port" to the agent-adoption checklist, because that is the part that generalises past this advisory.
29 September 202611 verified claims7 sources
Your coding agent runs a web server on your laptop. Any site you visit can reach it.
On 24 September, Datadog published what that cost.
Christophe Tafani-Dereeper of Datadog Security Labs disclosed GHSA-632h-h47v-g4x4 in OpenCode: a malicious webpage could POST to the agent's local /global/upgrade endpoint and get a package of the attacker's choosing installed. Reported 11 August, fixed 24 August in v1.18.22, published 24 September. 82 releases affected — 1.14.30 through 1.18.21.
Three things before you file it as someone else's CVE.
1. The trick is boring, which is why it worked. The endpoint parsed the body as JSON without checking Content-Type, so an HTML form with enctype="text/plain" — a submission browsers permit cross-origin — reached it. Then npm install -g opencode-ai@${target} ran, and npm reads a target as a specifier: a semver range, or a URL to a tarball. A preinstall script in the tarball did the rest.
2. The number to watch is not the severity, it is the propagation. In the week of 17–23 September, a month after the fix was available, 647,000 downloads were still of vulnerable versions — 38.9% of all OpenCode downloads that week. Caveat it honestly: a download is not a machine. CI runs, mirrors and pinned lockfiles are in there. But it is a floor, and the floor is high.
3. The CRA does not reach this one yet. Article 14's reporting duty went live on 11 September 2026 — 24 hours to an early warning, via ENISA's Single Reporting Platform. It triggers on actively exploited vulnerabilities, and nobody has claimed exploitation here. The limb that speaks to this sits in Annex I: limit attack surfaces, including external interfaces, and ensure vulnerabilities can be addressed through security updates. Those essential requirements apply from 11 December 2027.
Monday:
1. Do not grep for OpenCode. Run ss -ltnp and ask which of those listeners an agent opened.
2. opencode serve and opencode web without a password are the precondition, not the bug. Treat localhost as a public origin.
3. Put a version floor — opencode-ai >= 1.18.22 — in your dev-environment baseline, not only your production SBOM.
4. Add "does it open a port" to the agent-adoption checklist. That is the part that generalises.
The upgrade path is an external interface. December 2027 will say so out loud.
What is listening on your machine right now?
#CyberResilienceAct #AgenticAI #AppSec #DevSecOps #SoftwareEngineering
Corrections
What changed after publication
The aggregator sweep surfaced this as "OpenCode AI coding agent flaw lets malicious websites execute code on developer machines", carried by several outlets in the last week of September. Four things were corrected before publication:
- **Coverage date is not event date.** The public disclosure date is 24 September 2026, taken from Datadog Security Labs' own post and from the GitHub advisory, not from the aggregator's dateline.
- **The identifier, not the topic.** The late-September articles interleave this advisory with CVE-2026-22812 and CVE-2026-22813. Those are distinct, earlier OpenCode flaws with advisories published 12 January 2026 (GHSA-vxw4-wv6m-9hhh and GHSA-c83v-7274-4vgp), the latter fixed in 1.1.10. The edition is about GHSA-632h-h47v-g4x4 only, and the first comment says so explicitly.
- **Credit taken from the work's own front matter.** A GitHub advisory listing page rendered a reporter attribution that disagreed with the advisory itself. The advisory page and the finder's own write-up both name Christophe Tafani-Dereeper of Datadog Security Labs; that is what is used. No reporter credit is asserted for the January advisories.
- **A subpoint letter not asserted.** The CRA Annex I rendering that was reachable carries the 15.9.2022 proposal lettering, so the subpoint letters were not verified against the Official Journal text of Regulation (EU) 2024/2847. The edition cites Annex I, Part I, point (2) and the substance only; no letter is claimed. Recorded in the archived source PDF as a caveat.
Considered and dropped: Plugin4Shell (zero-click RCE across four coding agents, Help Net Security, 18 September) — a stronger headline but eleven days old and adjacent to ground the 21st and 24th already covered. Also dropped: the "MCP Deadbugz + 3 server CVEs" round-up, whose only dates are the newsletter's own (see D75).
Held back: the per-machine exposure figure. 647,000 downloads is not 647,000 developers, and no source gives a unique-installation count. The post carries the download figure with that caveat stated rather than converting it into a headcount.