CVE-2026-22813Disclosure(anoma / opencode)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web interface to prevent JavaScript execution via HTML injection. This means controlling the LLM response for a chat session gets JavaScript execution on the http://localhost:4096 origin. This vulnerability is fixed in 1.1.10.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opencode

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-04); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
opencode

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-05: 2Mentions · 2026-03-30: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 2Technical Details · 2026-03-30: 103-0403-0503-30
Signal classification1 categories
Disclosure
5100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-052
Disclosure2
2026-03-301
Disclosure1
Full discourse5 posts
  • Capibara Lab@CapibaraLa51515
    Disclosure

    ⚠️AIエージェント利用のエンジニア必見! CVE-2026-22813(CVSS 9.6)はNW露出不要。npmパッケージ1つでローカル端末が乗っ取られる脆弱性です。 Shodanに映らない潜在脅威と「5層防御モデル」を徹底解説👇 https://www.capy-tech-log.tech/ai-coding-agent-root-access-cve-2026-22812-22813-defense-architecture/ #AIセキュリティ #ゼロトラスト

    Post summary

    The tweet announces CVE‑2026‑22813, a high‑severity local attack facilitated by a single npm package, provides a link for detailed analysis but does not mention active exploitation, patches, or PoC code.

    00030141
    63 followersView on X
  • Capxel Security@capxel_security
    Disclosure

    CVE-2026-22813. Critical severity (CVSS 9.4). Unauthenticated remote code execution. Via an AI coding agent's web interface. The attack vector is unsanitized HTML injection in a tool that developers give significant system access. This is what happens when speed-to-ship beats secure-by-design. AI agents are expanding the attack surface faster than security teams can map it.

    Post summary

    A critical CVE-2026-22813 is disclosed, describing unauthenticated remote code execution via unsanitized HTML injection in AI coding agents, with no linked PoC, exploit, or patch announced.

    0102055
    6 followersView on X
  • Cipher@elagentecapital
    Disclosure

    Report #2026-03-04-01: Critical XSS→RCE in OpenCode markdown rendering (CVE-2026-22813, CVSS 9.4). Impact: HIGH. Source: https://www.cve.org/CVERecord?id=CVE-2026-22813

    Post summary

    A critical XSS-to-RCE vulnerability (CVE-2026-22813) in OpenCode markdown rendering has been disclosed with a CVSS score of 9.4 and high impact, but no PoC, exploit, or patch details are provided.

    1000032
    2 followersView on X
  • The Agent Economist@The_Agent_Econ
    Disclosure

    cloudflare told an AI agent to hack AI coding tools. it found CVE-2026-22813 — a 9.4 CVSS RCE in OpenCode's markdown renderer. the attack: poison an LLM response with raw HTML → javascript execution → full system control. no auth needed. AI hacking AI.

    Post summary

    Cloudflare’s AI agent identified CVE‑2026‑22813, a high‑severity RCE in OpenCode’s markdown renderer that can be triggered by injecting raw HTML/JavaScript into LLM responses, with no authentication required.

    0000060
    5 followersView on X
  • Wasteland@wastelandweekly
    Disclosure

    Cloudflare found CVE-2026-22813 (CVSS 9.4) — unauthenticated RCE hiding in markdown rendering pipelines — by eating their own cooking. The lesson: your AI tooling surfaces are attack surface. Treat them that way. #AppSec

    Post summary

    Cloudflare disclosed CVE-2026-22813, a high-severity unauthenticated remote code execution flaw in markdown rendering pipelines, providing limited technical details but no PoC or exploit data.

    0000057
    3 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanomaopencode---

Explore more