Your coding agent runs a web server on your laptop. Any site you visit can reach it. On 24 September, Datadog published what that cost.

Christophe Tafani-Dereeper of Datadog Security Labs disclosed GHSA-632h-h47v-g4x4 in OpenCode: a malicious webpage could POST to the agent's local /global/upgrade endpoint and get a package of the attacker's choosing installed. Reported 11 August, fixed 24 August in v1.18.22, published 24 September. 82 releases affected — 1.14.30 through 1.18.21.

Three things before you file it as someone else's CVE.

1. The trick is boring, which is why it worked. The endpoint parsed the body as JSON without checking Content-Type, so an HTML form with enctype="text/plain" — a submission browsers permit cross-origin — reached it. Then npm install -g opencode-ai@${target} ran, and npm reads a target as a specifier: a semver range, or a URL to a tarball. A preinstall script in the tarball did the rest.

2. The number to watch is not the severity, it is the propagation. In the week of 17–23 September, a month after the fix was available, 647,000 downloads were still of vulnerable versions — 38.9% of all OpenCode downloads that week. Caveat it honestly: a download is not a machine. CI runs, mirrors and pinned lockfiles are in there. But it is a floor, and the floor is high.

3. The CRA does not reach this one yet. Article 14's reporting duty went live on 11 September 2026 — 24 hours to an early warning, via ENISA's Single Reporting Platform. It triggers on actively exploited vulnerabilities, and nobody has claimed exploitation here. The limb that speaks to this sits in Annex I: limit attack surfaces, including external interfaces, and ensure vulnerabilities can be addressed through security updates. Those essential requirements apply from 11 December 2027.

Monday:

1. Do not grep for OpenCode. Run ss -ltnp and ask which of those listeners an agent opened. 2. opencode serve and opencode web without a password are the precondition, not the bug. Treat localhost as a public origin. 3. Put a version floor — opencode-ai >= 1.18.22 — in your dev-environment baseline, not only your production SBOM. 4. Add "does it open a port" to the agent-adoption checklist. That is the part that generalises.

The upgrade path is an external interface. December 2027 will say so out loud.

What is listening on your machine right now?

#CyberResilienceAct #AgenticAI #AppSec #DevSecOps #SoftwareEngineering