Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-64651— AI SDK OpenCode Harness Tool Relay Authorization Bypass

Quick assessment

Affected
vercel @ai-sdk/harness-opencode
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Vercel AI SDK是Vercel公司开源的一个TypeScript的AI工具包。 Vercel AI SDK 1.0.28之前版本存在授权问题漏洞,该漏洞源于工具中继授权机制缺陷,允许沙箱中执行的未信任代码调用任意主机暴露的工具,包括机密查找、部署操作和云API调用。

AI Predicted 9.8 Difficulty: Easy EPSS 0.16% · P5

Affected Version Matrix 1

VendorProduct Version RangeStatus
vercel @ai-sdk/harness-opencode < 1.0.29 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-64651

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AI SDK OpenCode Harness Tool Relay Authorization Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.28, the tool relay authorizes requests from any process whose command line contains an allowed helper script path (`host-tool-mcp.mjs`). This allows untrusted code executing in the sandbox to invoke arbitrary host-exposed tools including secret lookups, deployment operations, and cloud API calls without a corresponding model-authorized tool-call event. Exploitation requires a Linux environment (the vulnerable fallback checks `process.platform === 'linux'` and reads `/proc`); an active harness session with one or more host-provided tools; and untrusted code executing in the sandbox (e.g. a malicious dependency, build script, or lifecycle hook) The fix in version 1.0.28 removes the process-path authorization fallback entirely. Relay requests are now only accepted after exact, short-lived, one-time authorization matching the tool name and input from a bridge-observed model event. Some workarounds are available. Do not run the OpenCode harness on untrusted repositories or with untrusted dependencies, and/or limit host-exposed tools to non-sensitive operations when working with untrusted code.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5
Vulnerability Title
Vercel AI SDK 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Vercel AI SDK是Vercel公司开源的一个TypeScript的AI工具包。 Vercel AI SDK 1.0.28之前版本存在授权问题漏洞,该漏洞源于工具中继授权机制缺陷,允许沙箱中执行的未信任代码调用任意主机暴露的工具,包括机密查找、部署操作和云API调用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
vercel @ai-sdk/harness-opencode < 1.0.29 -

II. Public POCs for CVE-2026-64651

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-64651

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-64651 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-64651

No comments yet


Leave a comment