CRITICALVulnerability
CVE-2026-88899
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
Properties
- severity
- CRITICAL
- score
- 9.8
- cve_id
- CVE-2026-88899
- signal_observed_at
- 2026-09-18T05:40:02+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-09-10T16:18:12.120
- last_modified
- 2026-09-11T21:17:55.460
Related Entities (2)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]External Control of File Name or Path
Explore deeper with Ninja Signal's threat intelligence graph