OpenCode developer thdxr has announced the resolution of a critical security vulnerability discovered by a Cloudflare security researcher. The flaw involved a web front-end parameter that could be exploited to direct users to malicious servers. By embedding inline scripts in forged Markdown sessions, attackers could trick users into clicking links that execute arbitrary commands on their computers via terminal API. The official fix includes disabling the parameter, adding CSP headers, and enforcing password verification.
DeFiLlama founder 0xngmi commented on the issue, noting that a similar vulnerability was previously found in Cursor, which allowed arbitrary code execution on any computer with the software installed. He speculated that the pressure of AI competition might have led to security oversights in product delivery.
OpenCode Developer Fixes Critical Security Vulnerability
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
