CVE-2026-22813
EUVD-2026-209112.01.2026, 23:15
OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web interface to prevent JavaScript execution via HTML injection. This means controlling the LLM response for a chat session gets JavaScript execution on the http://localhost:4096 origin. This vulnerability is fixed in 1.1.10.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| anoma | opencode | 𝑥 < 1.1.10 |
𝑥
= Vulnerable software versions