GHSA-w47m-jpv2-qfw5CriticalCVSS 9.8

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header...

Published
September 10, 2026
Last Modified
September 10, 2026

🔗 CVE IDs covered (1)

📋 Description

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.

🔗 References (7)