OpenCode’s maintainers disclose that GHSA-pffc-58xr-hggc is a security vulnerability requiring remediation to protect coding-agent users and projects from compromise.
state: expiredheat: lowuncertainty: highknownscott: mediumagentic-security coding-agents supply-chain-securityOpenCodeAnomaly
What is this?
OpenCode is an open-source AI coding agent that, before version 1.0.216, automatically started an unauthenticated local HTTP server with permissive CORS, allowing local processes or websites to execute shell commands with the user’s privileges. NVD and GitHub identify this remote-code-execution flaw as CVE-2026-22812 / GHSA-vxw4-wv6m-9hhh and say it was fixed in version 1.0.216. The supplied evidence does not establish the case’s cited GHSA-pffc-58xr-hggc, nor clearly show a maintainer disclosure by OpenCode or Anomaly; another result discusses a separate vulnerability fixed in 1.1.10.
Why it matters to Scott
Scott already argues in SiloOS and Architecture, Not Vibes that coding agents with shell authority require structural containment rather than trusted defaults. The reported unauthenticated, permissive-CORS command surface is a concrete audit trigger for his own HTTP/MCP services, especially the E-book MCP server where no authentication was implemented; however, the supplied evidence does not validate the case’s cited GHSA or claimed OpenCode/Anomaly maintainer disclosure.
ip:framework.siloosip:framework.architecture-not-vibesip:concept.sandboxed-executiondev:project.mcp-ip-wikidev:project.ebook-mcpradar:secure-browser-mcp-runtimeradar:remote-mcp-auth-exposure-studyradar:concept.agent-securityradar:concept.api-attacks
queries asked of Scott's wikis
- coding-agent privilege and trust boundaries
- agent harness sandboxing and command authorization
- localhost services permissive CORS threat model
- prompt injection to tool execution pathways
- coding-agent supply-chain security controls
- secure defaults for autonomous developer tools
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (1) — ⭐ canonical anchor
Interpretation history
2026-08-28T18:39:04Z
The specific GHSA-to-OpenCode claim remains unsupported after the verification horizon and appears likely conflated with other established OpenCode advisories. Preserve the broader security context, but retire this episode unless direct advisory evidence later appears.
2026-08-26T17:40:50Z
The short verification window elapsed without first-party advisory text or any independent evidence tying GHSA-pffc-58xr-hggc to OpenCode. The known OpenCode vulnerabilities remain relevant context, but this specific episode is still an unverified and potentially conflated claim.
2026-08-26T13:39:55Z
No substantive evidence has arrived to validate the cited GHSA or connect it to an OpenCode maintainer disclosure; the mismatch with the separately grounded OpenCode advisories remains unresolved. Keep the case provisional pending the advisory text rather than treating the HN title as confirmation.
2026-08-26T13:38:06Z
grounded: known/medium — Scott already argues in SiloOS and Architecture, Not Vibes that coding agents with shell authority require structural containment rather than trusted defaults.
2026-08-26T13:35:27Z
case created — A maintainer-hosted GitHub security advisory is a concrete coding-agent security event even before independent reproduction or wider exploitation evidence.
Decision trace
- 08-29 04:39expireThe specific GHSA-to-OpenCode claim remains unsupported after the verification horizon and appears likely conflated with other established OpenCode advisories. Preserve the broader security context, b
- 08-29 04:39alert_silentNo new evidence arrived at the 48-hour staleness check, and the lone HN title still cannot establish the named advisory or maintainer disclosure. There is no consequential new delta to surface or reas
- 08-29 04:39alert_routeNo new evidence arrived at the 48-hour staleness check, and the lone HN title still cannot establish the named advisory or maintainer disclosure. There is no consequential new delta to surface or reas
- 08-27 03:40repriceThe short verification window elapsed without first-party advisory text or any independent evidence tying GHSA-pffc-58xr-hggc to OpenCode. The known OpenCode vulnerabilities remain relevant context, b
- 08-27 03:40alert_silentThe named release condition was not met, and the unchanged low-information HN title cannot establish that this specific advisory exists or applies to OpenCode. With no new consequential delta, extendi
- 08-27 03:40alert_routeThe named release condition was not met, and the unchanged low-information HN title cannot establish that this specific advisory exists or applies to OpenCode. With no new consequential delta, extendi
- 08-26 23:39repriceNo substantive evidence has arrived to validate the cited GHSA or connect it to an OpenCode maintainer disclosure; the mismatch with the separately grounded OpenCode advisories remains unresolved. Kee
- 08-26 23:39alert_holdThe prior short hold remains appropriate because the specific first-party advisory page can quickly establish or invalidate the event, while alerting from the unchanged HN title would risk conflating
- 08-26 23:39surface_candidateThe prior short hold remains appropriate because the specific first-party advisory page can quickly establish or invalidate the event, while alerting from the unchanged HN title would risk conflating
- 08-26 23:39alert_routeThe prior short hold remains appropriate because the specific first-party advisory page can quickly establish or invalidate the event, while alerting from the unchanged HN title would risk conflating
- 08-26 23:38alert_holdThe specific GitHub advisory URL makes this substantive enough for a short hold, but the supplied evidence contains no first-party advisory text confirming that the vulnerability was published or requ
- 08-26 23:38alert_routeThe specific GitHub advisory URL makes this substantive enough for a short hold, but the supplied evidence contains no first-party advisory text confirming that the vulnerability was published or requ
- 08-26 23:38groundScott already argues in SiloOS and Architecture, Not Vibes that coding agents with shell authority require structural containment rather than trusted defaults. The reported unauthenticated, permissive
- 08-26 23:35createA maintainer-hosted GitHub security advisory is a concrete coding-agent security event even before independent reproduction or wider exploitation evidence.