Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c83v-7274-4vgp | Malicious website can execute commands on the local system through XSS in the OpenCode web UI |
Wed, 21 Jan 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anoma
Anoma opencode |
|
| CPEs | cpe:2.3:a:anoma:opencode:*:*:*:*:*:-:*:* | |
| Vendors & Products |
Anoma
Anoma opencode |
|
| Metrics |
cvssV3_1
|
Tue, 13 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anomalyco
Anomalyco opencode |
|
| Vendors & Products |
Anomalyco
Anomalyco opencode |
Mon, 12 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web interface to prevent JavaScript execution via HTML injection. This means controlling the LLM response for a chat session gets JavaScript execution on the http://localhost:4096 origin. This vulnerability is fixed in 1.1.10. | |
| Title | Malicious website can execute commands on the local system through XSS in the OpenCode web UI | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-13T19:07:23.038Z
Reserved: 2026-01-09T22:50:10.288Z
Link: CVE-2026-22813
Updated: 2026-01-13T14:13:32.507Z
Status : Analyzed
Published: 2026-01-12T23:15:53.523
Modified: 2026-01-21T15:15:35.597
Link: CVE-2026-22813
No data.
OpenCVE Enrichment
Updated: 2026-04-18T07:00:11Z
Github GHSA