What happened
Datadog Security Labs found a critical remote code execution in the OpenCode AI coding agent's browser interface: the /global/upgrade API combined content-type confusion in the raw request handler with unsafe handling of an attacker-controlled upgrade target, letting a malicious website substitute an on-path npm tarball with a malicious package.json lifecycle script. The exploit requires only that a user running an affected version visits the crafted page while the local agent server is active.
Why it matters
An AI coding agent is the highest-trust surface on a developer's machine — it holds the user's credentials, repo access, and shell privileges. Compromising it via a benign webpage visit converts an everyday browsing action into full code execution in the agent host, directly enabling code-supply-chain poisoning and credential theft for anyone writing AI-assisted code.
Attack vector
Crafted web page visited while OpenCode's web interface is running (opencode serve/web on 127.0.0.1:4096) triggers a content-type-confusion path: the /global/upgrade endpoint passes an attacker-controlled upgrade target into a package-manager install command, and npm package specs accept remote tarball URLs — so a hidden-form/text-plain request can direct the install to a malicious package whose preinstall lifecycle script runs with the OpenCode process's privileges. The unauthenticated localhost service is reachable from a hostile page via top-level HTML form navigation (bypassing CORS). No CVE was requested; track the GitHub advisory.
Affected systems
OpenCode 1.14.30–1.18.21 (installed via npm/pnpm/Bun); fixed in 1.18.22; GitHub advisory GHSA-632h-h47v-g4x4
Mitigation
Upgrade to OpenCode 1.18.22+ (validates the upgrade target as a semantic version and rejects text/plain bodies). Defense in depth: set OPENCODE_SERVER_PASSWORD, do not expose the service beyond localhost, treat sudden package-manager activity as compromise evidence