OpenCode AI 編碼代理程式爆發關鍵未驗證遠端程式碼執行與檔案讀取漏洞

OpenCode AI 編碼代理程式爆發關鍵未驗證遠端程式碼執行與檔案讀取漏洞

Hacker News·

OpenCode AI 編碼代理程式被發現存在關鍵安全漏洞,包括未經驗證的遠端程式碼執行(RCE)和檔案讀取漏洞。這些問題允許任何網站利用該系統。

Navigation Menu

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

To see all available qualifiers, see our documentation.

Uh oh!

There was an error while loading. Please reload this page.

RCE and file read vulnerability #6355

Image

Image

Description

Image

Description

Vulnerability Summary

The OpenCode codebase has critical security vulnerabilities:

Attack Vector

Any website can:

OpenCode version

1.0.207

Steps to reproduce

Screenshot and/or share link

No response

Operating System

macos

Terminal

iTerm2

Metadata

Metadata

Assignees

Image

Labels

Type

Projects

Milestone

Relationships

Development

Issue actions

Footer

Footer navigation

Hacker News

相關文章

  1. 代理閱讀測試:衡量 AI 編碼代理網頁內容閱讀能力的基準測試

    17 天前

  2. Show HN:AI Code Guard – AI 生成程式碼的安全掃描器

    3 個月前

  3. AI發現零日未驗證遠端程式碼執行漏洞,影響全球七萬台連網裝置

    4 個月前

  4. 我們如何監控內部程式編寫代理的對齊失誤

    OpenAI · 大約 1 個月前

  5. 一鍵遠端程式碼執行漏洞,可竊取 Moltbot 資料與金鑰

    3 個月前