OpenCode AI Coding Agent Vulnerable to Remote Code Execution
A critical vulnerability in the popular OpenCode AI coding agent allows malicious websites to execute arbitrary code on developer machines.

A critical remote code execution (RCE) vulnerability has been discovered in the widely-used OpenCode AI coding agent, potentially exposing thousands of developers to malicious attacks. The flaw, identified as GHSA-632h-h47v-g4x4, affects versions 1.14.30 through 1.18.21 of the agent when installed via npm, pnpm, or Bun. This vulnerability could allow a malicious website to trick a developer into executing arbitrary commands on their local machine.
The exploit leverages a content-type confusion within OpenCode's /global/upgrade API. Attackers can craft a malicious HTML form that, when visited by a developer running an affected OpenCode instance, tricks the browser into sending a request to the local OpenCode server. This request, disguised as a legitimate upgrade operation, can be manipulated to point to an attacker-controlled package tarball. When OpenCode attempts to install this malicious package, it inadvertently executes a preinstall lifecycle script embedded within it, leading to RCE.
Researchers at Datadog Security Labs detailed how the exploit bypasses typical browser security mechanisms like CORS and Local Network Access protections. The core weakness lies in OpenCode's raw request handler, which failed to properly validate the declared content type before attempting to parse the request body as JSON. By using specific HTML form encoding (enctype=”text/plain”) and carefully crafted field names, attackers can construct a valid JSON payload that directs the upgrade endpoint to their malicious package.
OpenCode, launched in June 2025, integrates AI models into developer workflows and boasts significant popularity with over 208,000 GitHub stars and an estimated 16 million monthly developers. The affected component is the agent's browser interface, typically accessible via opencode serve or opencode web on localhost:4096, which often runs without authentication by default.
Analysis of npm download statistics revealed that between September 17 and 23, 2026, vulnerable versions of OpenCode recorded over 647,000 downloads, representing nearly 39% of all OpenCode downloads during that period. While this figure doesn't indicate unique installations or active web service usage, it highlights the substantial potential attack surface.
Anomaly, the developer behind OpenCode, has released version 1.18.22 to patch the vulnerability. The fix includes validating the upgrade target as a semantic version to prevent arbitrary package URLs and implementing a content-aware handler that rejects non-JSON content types, such as text/plain, for the upgrade endpoint.
Developers using affected versions are strongly advised to upgrade immediately to OpenCode 1.18.22 or later. They should also restart any active OpenCode processes, verify their installation method, and enable password protection for the web interface using the OPENCODE_SERVER_PASSWORD environment variable. While password protection mitigates some risks, it does not replace the critical need for patching, as cached browser credentials could still be exploited.
This incident underscores the growing security risks associated with AI-powered developer tools. As these agents become more integrated into development workflows, ensuring their security and preventing them from becoming attack vectors is paramount for maintaining software supply-chain integrity.