OpenCode Sandbox Escape: Unauth Header Injection Grants Host Filesystem RCE
Security Advisory
Critical
OpenCode
Affected:
- OpenCode v5.0.30 and earlier
Fixed in:
- v5.0.30
Referenced CVEs:
CVE-2026-88899 · 9.8
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.