Threat · curated 3 Oct 2026
Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4) | Datadog Security Labs
First reported datadoghq.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
OpenCode is a widely deployed AI coding agent whose web interface runs unauthenticated by default, so an RCE in its upgrade endpoint lets attackers execute code on developer machines running the agent.
Datadog Security Labs discovered and demonstrated GHSA-632h-h47v-g4x4, a remote code execution vulnerability in OpenCode, an open-source AI coding agent with 16 million monthly users. A content-type confusion in the `/global/upgrade` API endpoint made an underlying code injection flaw exploitable, including against the web interface which by default requires no authentication. OpenCode 1.18.22 fixes the vulnerability.