Threat · curated 3 Oct 2026

Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4) | Datadog Security Labs

Coverage timeline

24 Sep 2026datadoghq.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

OpenCode is a widely deployed AI coding agent whose web interface runs unauthenticated by default, so an RCE in its upgrade endpoint lets attackers execute code on developer machines running the agent.

Datadog Security Labs discovered and demonstrated GHSA-632h-h47v-g4x4, a remote code execution vulnerability in OpenCode, an open-source AI coding agent with 16 million monthly users. A content-type confusion in the `/global/upgrade` API endpoint made an underlying code injection flaw exploitable, including against the web interface which by default requires no authentication. OpenCode 1.18.22 fixes the vulnerability.