NullSecurityX[verified]@NullSecurityXDisclosure
The tweet announces CVE-2026-22812, an unauthenticated remote code execution flaw in OpenCode v1.0.216, with no exploit code, active exploitation, or patch details provided.
NullSecurityX[verified]@NullSecurityXPatch
CVE-2026-22812 allows unauthenticated remote code execution in OpenCode via a specific POST endpoint, and users are advised to update to v1.0.216 immediately to mitigate the risk.
Professor Larry Densel[verified]@luckyhacker43Patch
The post provides technical details of an RCE vulnerability and highlights a patch, without indicating active exploitation or a PoC.
Professor Larry Densel[verified]@luckyhacker43Disclosure
The tweet announces CVE-2026‑22812, noting that OpenCode’s unauthenticated HTTP server permits arbitrary command execution, but offers no PoC, exploit, patch, or active exploitation details.
𝕏 Bug Bounty Writeups 𝕏[verified]@bountywriteupsExploit
The Medium post outlines a successful RCE on the targeted AI coding tool, including exploit details and likely code, but offers no evidence of ongoing active attacks or official patches.
0x0smilex@0x0smilexPatch
The tweet alerts OpenCode users to CVE‑2026‑22812, an unauthenticated remote code execution flaw in the /session/{id}/shell endpoint, and urges an upgrade to v1.0.216 to mitigate the vulnerability.
Capibara Lab@CapibaraLa51515Disclosure
The post announces CVE‑2026‑22813 as a high‑score vulnerability that can be exploited locally via a single npm package, without network exposure; no PoC, exploit, or patch is mentioned.
KaTsuShi Tamagawa@ryusunsaDisclosure
The post announces CVE-2026-22812 affecting a popular OSS coding agent, noting a full bypass of bash filters and destructive impact on prompt cache, but offers no exploit code, patch, or evidence of active exploitation.