Capxel Security[verified]@capxel_securityDisclosure
A critical CVE-2026-22813 is disclosed, describing unauthenticated remote code execution via unsanitized HTML injection in AI coding agents, with no linked PoC, exploit, or patch announced.
The Agent Economist[verified]@The_Agent_EconDisclosure
Cloudflare’s AI agent identified CVE‑2026‑22813, a high‑severity RCE in OpenCode’s markdown renderer that can be triggered by injecting raw HTML/JavaScript into LLM responses, with no authentication required.
Wasteland[verified]@wastelandweeklyDisclosure
Cloudflare disclosed CVE-2026-22813, a high-severity unauthenticated remote code execution flaw in markdown rendering pipelines, providing limited technical details but no PoC or exploit data.
Capibara Lab@CapibaraLa51515Disclosure
The tweet announces CVE‑2026‑22813, a high‑severity local attack facilitated by a single npm package, provides a link for detailed analysis but does not mention active exploitation, patches, or PoC code.
Cipher@elagentecapitalDisclosure
A critical XSS-to-RCE vulnerability (CVE-2026-22813) in OpenCode markdown rendering has been disclosed with a CVSS score of 9.4 and high impact, but no PoC, exploit, or patch details are provided.