PkgRadar

Malware advisory

GHSA-c83v-7274-4vgp

Malicious website can execute commands on the local system through XSS in the OpenCode web UI

4 affected releases in the PkgRadar corpus · published 2026-01-13 · upstream advisory

Affected packages

PackageEcosystemVersionVerdictScanned (UTC)
opencode-ainpm0.0.0-dev-202605250153Review2026-05-25
opencode-ainpm0.0.0-dev-202605250758Review2026-05-25
opencode-ainpm0.0.0-beta-202605251010Review2026-05-25
opencode-ainpm0.0.0-dev-202605250943Review2026-05-25

PkgRadar blocks these releases at the CI gate before they reach your build. Start free or see all advisories.