Datadog Details OpenCode Remote Code Execution Vulnerability and Exploit

Summary
Datadog Security Labs describes an OpenCode RCE flaw (GHSA-632h-h47v-g4x4) that let a malicious webpage trigger installation of an attacker-hosted npm tarball. Versions 1.14.30–1.18.21 were affected; OpenCode 1.18.22 fixes it.
Key points
- A content-type confusion in OpenCode’s `/global/upgrade` endpoint let an attacker-controlled package URL reach the package manager as an install target.
- The exploit uses a malicious webpage to submit a cross-origin top-level HTML form with `text/plain`; the installed package’s preinstall script can then execute code on the machine running OpenCode.
- Affected versions are 1.14.30 through 1.18.21 when installed through npm, pnpm, or Bun.
- Exploitation also requires `opencode serve` or `opencode web` to be running without password authentication, or browser credentials to be cached.
- OpenCode 1.18.22 fixes the issue by requiring a semantic-version target and validating request content types.
- Vulnerable versions received more than 647,000 npm downloads from September 17–23, 2026; the figure does not indicate unique users or affected machines.
Article Details
- Attack Vectors
- In OpenCode 1.14.30 through 1.18.21, the /global/upgrade endpoint accepted a text/plain request body containing JSON without enforcing the expected content type.
- A malicious webpage could submit a cross-origin HTML form as a top-level navigation to a locally running OpenCode server, bypassing the browser protections described for cross-origin fetch requests.
- The upgrade target accepted a remote package tarball URL. When OpenCode was installed through npm, pnpm, or Bun, upgrading from an attacker-hosted tarball could execute its preinstall script.
- Defensive Notes
- Upgrade to OpenCode 1.18.22, which restricts upgrade targets to semantic versions and enforces request content type.
- The reported exploit conditions require a vulnerable OpenCode version installed through npm, pnpm, or Bun, with opencode serve or opencode web running without password authentication or with credentials cached in the browser.
- Enable password authentication when exposing the OpenCode web interface to a network.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| URL | hxxp[:]//165[.]227[.]82[.]252:4444/ | Referrer URL for the malicious webpage in the researchers' exploit demonstration. |
| URL | hxxp[:]//165[.]227[.]82[.]252/opencode-malicious[.]tgz | Attacker-hosted malicious package tarball URL used in the researchers' exploit demonstration. |