⚠️ Discovering and exploiting a remote code execution vulnerability in OpenCode
Datadog Security Labs found GHSA-632h-h47v-g4x4 in OpenCode: the unauthenticated /global/upgrade API endpoint accepted arbitrary npm tarball URLs, enabling RCE via a crafted cross-origin HTML form submission bypassing CORS.
https://securitylabs.datadoghq.com/articles/opencode-upgrade-remote-code-execution
#RCE
Post #1582
130

- ❤ 1
- 👍 1
- 🔥 1