A critical attack path in OpenCode, an open-source AI coding agent, could let a malicious website execute commands on a developer’s computer. Tracked as GHSA-632h-h47v-g4x4, the remote code execution vulnerability combines content-type confusion in OpenCode’s /global/upgrade API with unsafe handling of an attacker-controlled upgrade target.... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
OpenCode AI Coding Agent Flaw Lets Malicious Websites Execute Code on Developer Machines
A critical attack path in OpenCode, an open-source AI coding agent, could let a malicious website execute commands on a developer’s computer. Tracked as GHSA-632h-h47v-g4x4, the remote code execution vulnerability combines content-type con…
Reagiere als Erste:r — dein Feedback zählt!
2. Cyber Threat Intelligence & Forensik
CTI Threat Relationship Graph3 Knoten / 2 Relationen
MITRE ATT&CK Matrix Navigator 14 Taktiken
1 belegte TechnikenLive-Mapping
Reconnaissance
–
Resource Development
–
Initial Access
Execution
–
Persistence
–
Privilege Escalation
–
Defense Evasion
–
Credential Access
–
Discovery
–
Lateral Movement
–
Collection
–
Command and Control
–
Exfiltration
–
Impact
–