Vulnerability Description
OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web interface to prevent JavaScript execution via HTML injection. This means controlling the LLM response for a chat session gets JavaScript execution on the http://localhost:4096 origin. This vulnerability is fixed in 1.1.10.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Anoma | Opencode | < 1.1.10 |
Related Weaknesses (CWE)
References
- https://github.com/anomalyco/opencode/security/advisories/GHSA-c83v-7274-4vgpVendor AdvisoryExploit
- https://github.com/anomalyco/opencode/security/advisories/GHSA-c83v-7274-4vgpVendor AdvisoryExploit
FAQ
What is CVE-2026-22813?
CVE-2026-22813 is a vulnerability with a CVSS score of 6.1 (MEDIUM). OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web inter...
How severe is CVE-2026-22813?
CVE-2026-22813 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-22813?
Check the references section above for vendor advisories and patch information. Affected products include: Anoma Opencode.