Skip to content
Remote Code Execution Vulnerabilities Found in OpenCode and OpenMed

Remote Code Execution Vulnerabilities Found in OpenCode and OpenMed

First seen 24 Sep 2026, 19:56 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 24, 2026 at 20:52 UTC
  • •OpenCode vulnerability allows remote code execution via crafted npm packages.
  • •Anomaly chose not to request a CVE for the OpenCode vulnerability.
  • •AI-assisted workflows identified multiple RCE vulnerabilities in other projects.

A remote code execution (RCE) vulnerability (GHSA-632h-h47v-g4x4) was discovered in OpenCode, an open-source AI coding agent, affecting versions prior to 1.18.22. The vulnerability arises from a content-type confusion in the /global/upgrade API endpoint, allowing attackers to execute malicious code through crafted npm packages. Anomaly, the developer of OpenCode, has opted not to request a CVE for this issue. In a related context, AI-assisted vulnerability discovery has revealed multiple RCE vulnerabilities in other projects, including OpenMed, which has a CVSS score of 9.8. The vulnerabilities in OpenMed and others were identified through AI workflows, emphasizing the need for AI in secure software development. The OpenCode vulnerability is currently exploitable, and users are urged to upgrade to version 1.18.22 to mitigate the risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-02
CVE-2026-47117 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-17
CVE-2026-47103 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-18
CVE-2026-9147 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-27
CVE-2026-10036 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
AI-assisted vulnerabilities disclosed
AI workflows revealed multiple RCE vulnerabilities in various projects, including OpenMed, which has a CVSS score of 9.8.
Sdtimes
2026-09-24
OpenCode vulnerability announced
GHSA-632h-h47v-g4x4 vulnerability in OpenCode allows RCE through a content-type confusion in the /global/upgrade API.
Securitylabs.Datadoghq
2026-09-24
OpenCode patch released
OpenCode version 1.18.22 was released to fix the RCE vulnerability, urging users to upgrade immediately.
Securitylabs.Datadoghq

More articles in this cluster (3)

Following this threat?

Track CVE-2026-10036 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed