CVE-2026-22812Disclosure(anoma / opencode)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch anoma opencode systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-749CWE-942

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opencode

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 13 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 11 signals
  • Disclosure: 6 classified signals
  • Peaked 7d ago at 2 mentions (2026-03-21); latest day: 1
  • 14 total mentions across 13 days

Affected systems

Vendors
Products
opencode

Deep dive

Activity timeline14 mentions / 13d
01122Mentions · 2026-01-30: 1Mentions · 2026-01-31: 1Mentions · 2026-02-01: 1Mentions · 2026-02-02: 1Mentions · 2026-02-03: 1Mentions · 2026-03-21: 2Mentions · 2026-03-30: 1Mentions · 2026-04-01: 1Mentions · 2026-04-04: 1Mentions · 2026-07-23: 1Mentions · 2026-07-30: 1Mentions · 2026-08-15: 1Mentions · 2026-10-08: 1PoC Mentioned / Linked · 2026-01-31: 1PoC Mentioned / Linked · 2026-03-21: 1Exploit Tool / Code · 2026-01-31: 1Exploit Tool / Code · 2026-03-21: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-07-30: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-01: 1Technical Details · 2026-02-03: 1Technical Details · 2026-03-21: 2Technical Details · 2026-03-30: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-04: 1Technical Details · 2026-07-23: 1Technical Details · 2026-07-30: 1Technical Details · 2026-08-15: 101-3001-3102-0102-0202-0303-2103-3004-0104-0407-2307-3008-1510-08
Signal classification5 categories
Disclosure
646.2%
Patch
323.1%
Exploit
215.4%
General
17.7%
PoC
17.7%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-01-301
Patch1
2026-01-311
Exploit1
2026-02-011
Patch1
2026-02-021
General1
2026-02-031
Disclosure1
2026-03-212
Exploit1PoC1
2026-03-301
Disclosure1
2026-04-011
Disclosure1
2026-04-041
Disclosure1
2026-07-231
Disclosure1
2026-07-301
Patch1
2026-08-151
Disclosure1
Full discourse14 posts
  • NullSecurityX@NullSecurityX
    Disclosure

    CVE-2026-22812: OpenCode v1.0.216 - Unauthenticated RCE #BugBounty #CyberSecurity https://t.co/FIS3vz82wI

    Post summary

    The tweet announces CVE-2026-22812, an unauthenticated remote code execution flaw in OpenCode v1.0.216, with no exploit code, active exploitation, or patch details provided.

    159045424326.3K
    11.8K followersView on X
  • 0x0smilex@0x0smilex
    Patch

    If you're using OpenCode (AI coding agent), update to v1.0.216 NOW (CVE-2026-22812) 🚨. Unauth RCE via POST /session/{id}/shell. No login, no tokens, just direct command execution. eg: /etc/passwd and ...etc #BugBounty #OpenCode #bugbountytips #ethicalhacking https://t.co/3EFJb4IQF5

    Post summary

    The tweet alerts OpenCode users to CVE‑2026‑22812, an unauthenticated remote code execution flaw in the /session/{id}/shell endpoint, and urges an upgrade to v1.0.216 to mitigate the vulnerability.

    211078345.4K
    2.2K followersView on X
  • NullSecurityX@NullSecurityX
    Patch

    If you're using OpenCode (AI coding agent), update to v1.0.216 NOW (CVE-2026-22812) Unauth RCE via POST /session/{id}/shell. No login, no tokens, just direct command execution. eg: /etc/passwd and ...etc #BugBounty #CyberSecurity #Clawdbot #opencode https://t.co/RmxmStbh7m

    Post summary

    CVE-2026-22812 allows unauthenticated remote code execution in OpenCode via a specific POST endpoint, and users are advised to update to v1.0.216 immediately to mitigate the risk.

    15160193.2K
    9.1K followersView on X
  • Professor Larry Densel@luckyhacker43
    Patch

    [8.8] CVE-2026-22812: OpenCode RCE Unauthenticated HTTP server exposes /session/:id/shell, /pty, /file/content. Permissive CORS allows arbitrary command execution. Dark Exploit found it. Fix: Update to v1.0.216+ 🔗 http://miggo.io --- 🔗 http://t.me/luckyhacker42 https://t.co/6aAXwHpMdY

    Post summary

    The post provides technical details of an RCE vulnerability and highlights a patch, without indicating active exploitation or a PoC.

    012031131.7K
    4.6K followersView on X
  • Professor Larry Densel@luckyhacker43
    Disclosure

    [8.8] CVE-2026-22812: OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution 🔥 🔗 https://www.miggo.io/vulnerability-database/cve/CVE-2026-22812 🔗 JOIN TEAM 👉https://t.me/luckyhacker42 https://t.co/6UfvxqTXv7

    Post summary

    The tweet announces CVE-2026‑22812, noting that OpenCode’s unauthenticated HTTP server permits arbitrary command execution, but offers no PoC, exploit, patch, or active exploitation details.

    040198979
    5.0K followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Exploit

    CVE-2026–22812: How I Got RCE on a 71k-Star AI Coding Tool With Zero Authentication https://medium.com/@dhxrxx/cve-2026-22812-how-i-got-rce-on-a-71k-star-ai-coding-tool-with-zero-authentication-7524fbc3317f?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The Medium post outlines a successful RCE on the targeted AI coding tool, including exploit details and likely code, but offers no evidence of ongoing active attacks or official patches.

    010941.3K
    40.3K followersView on X
  • Dinislam Tebuev@tebuev

    @thdxr joky joke, referring to this https://www.cve.org/CVERecord?id=CVE-2026-22812

    00021574
    48 followersView on X
  • Capibara Lab@CapibaraLa51515
    Disclosure

    ⚠️AIエージェント利用のエンジニア必見! CVE-2026-22813(CVSS 9.6)はNW露出不要。npmパッケージ1つでローカル端末が乗っ取られる脆弱性です。 Shodanに映らない潜在脅威と「5層防御モデル」を徹底解説👇 https://www.capy-tech-log.tech/ai-coding-agent-root-access-cve-2026-22812-22813-defense-architecture/ #AIセキュリティ #ゼロトラスト

    Post summary

    The post announces CVE‑2026‑22813 as a high‑score vulnerability that can be exploited locally via a single npm package, without network exposure; no PoC, exploit, or patch is mentioned.

    00030141
    63 followersView on X
  • KaTsuShi Tamagawa@ryusunsa
    Disclosure

    【オープンコード…お前もか?】 GitHub 161k starsの最人気OSS coding agentに「今すぐ使うのをやめろ」と叫ぶ男が現れた。 CVE-2026-22812 / bashフィルタ全バイパス / プロンプトキャッシュ全滅戦争 note: https://note.com/famous_prawn2009/n/n2f60c4d45366 #AI #セキュリティ #OpenCode

    Post summary

    The post announces CVE-2026-22812 affecting a popular OSS coding agent, noting a full bypass of bash filters and destructive impact on prompt cache, but offers no exploit code, patch, or evidence of active exploitation.

    0011098
    69 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-22812 - high 🚨 OpenCode < 1.0.216 - Unauthenticated Remote Code Execution > OpenCode versions prior to 1.0.216 contain an unauthenticated remote code execution v... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-22812 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2026-22812 is a high‑severity unauthenticated remote code execution vulnerability affecting OpenCode versions prior to 1.0.216; the post does not provide any PoC, exploit code, patch, or evidence of active exploitation.

    00011194
    890 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-21509 2 - CVE-2026-22812 3 - CVE-2026-0755 4 - CVE-2025-43529 5 - CVE-2026-1281 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five CVE identifiers without providing any additional technical or contextual information.

    00020307
    1.7K followersView on X
  • Narahari Dasa@IamNarahariDasa
    Disclosure

    220,000 AI coding agent instances are publicly exposed with zero authentication. CVE-2026-22812. CVSS 8.8. Unauthenticated remote code execution. The number only counts servers. It doesn't count the Mac Minis.

    Post summary

    A newly disclosed CVE‑2026‑22812 with CVSS 8.8 exposes around 220,000 AI coding agent instances to unauthenticated remote code execution, yet no patches or active exploitation reports are mentioned.

    1000033
    24 followersView on X
  • ‘BBWriteups’@bbwriteup
    PoC

    "CVE-2026–22812: How I Got RCE on a 71k-Star AI Coding Tool With Zero Authentication" by Dharanis #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@dhxrxx/cve-2026-22812-how-i-got-rce-on-a-71k-star-ai-coding-tool-with-zero-authentication-7524fbc3317f

    Post summary

    A Medium article claims the author achieved remote code execution on an AI coding tool via CVE‑2026‑22812 without authentication, implying a PoC exists but no patch or active exploitation is reported.

    0000048
    532 followersView on X
  • BomboDiez@bombodiez10
    Exploit

    https://github.com/rohmatariow/CVE-2026-22812-exploit Todo el mundo explotando cosas😃los labs es el modo pve el verdadero juego es meterle amor a cosas chinas rotas🙂

    Post summary

    A GitHub repository linked in the text provides exploit code for CVE‑2026‑22812, indicating a functional exploit is available, but no evidence of active wild exploitation or mitigation is provided.

    0000078
    17 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanomaopencode---

Explore more