Preliminary research
OpenCode upgrade RCE: text/plain JSON, top-level navigation and package-install targets
Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4)
AI-collected research leads through 27 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
OpenCode parsed text/plain forms as JSON and accepted remote tarballs as upgrade targets. A top-level localhost request could run package scripts, with npm/pnpm/Bun installs and no password or cached Basic credentials.
Record
- Document
- Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4)
- Researcher
- Christophe Tafani-Dereeper
- Published by
- Datadog Security Labs
- Date
- Topic
- Supply
In the archive
Related sources
- Cross-site OpenCode server upgrade request can install arbitrary packages for npm-based installations Advisory
- fix(opencode): normalize upgrade endpoint
- Embedded demonstration
Tags
This page is the archive's own catalogue record. The research is the work of Christophe Tafani-Dereeper, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .