GHSA-w47m-jpv2-qfw5Critical· 9.8▾ MidnightDuplicate Advisory: Knowns Sandbox Escape: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-9h2q-r9fh-f98w. This link is maintained to preserve external references.
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
knowns < 0.31.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-88899Critical· 9.8knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header
GHSA-qjrq-cvv4-3g9wHigh· 8.8Duplicate Advisory: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
CVE-2026-86439High· 8.8knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory
CVE-2026-86775High· 8.6knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API
CVE-2026-88938Medium· 6.5knowns through 0.33.0 Path Traversal via code.find MCP tool
CVE-2026-88937High· 8.8knowns through 0.33.0 Path Traversal via Template Engine