CVE-2026-88899

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-10 16:18

Updated : 2026-09-11 21:17


NVD link : CVE-2026-88899

Mitre link : CVE-2026-88899

CVE.ORG link : CVE-2026-88899


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path