{"id":"CVE-2026-22813","aliases":["GHSA-c83v-7274-4vgp"],"url":"https://o3.security/vulnerability/CVE-2026-22813","summary":"Malicious website can execute commands on the local system through XSS in the OpenCode web UI","details":"OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web interface to prevent JavaScript execution via HTML injection. This means controlling the LLM response for a chat session gets JavaScript execution on the http://localhost:4096 origin. This vulnerability is fixed in 1.1.10.","published":"2026-01-12T22:52:35.103Z","modified":"2026-07-15T01:49:15.869601171Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"opencode-ai","fixedVersion":"1.1.10"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22813.json"},{"type":"ADVISORY","url":"https://github.com/anomalyco/opencode/security/advisories/GHSA-c83v-7274-4vgp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22813"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:15.869601171Z"}}