HTML Injection Vulnerability in OpenCode by Anomaly Co.
CVE-2026-22813
What is CVE-2026-22813?
OpenCode, an open source AI coding agent developed by Anomaly Co., contains a vulnerability in its markdown renderer that allows arbitrary HTML to be inserted into the Document Object Model (DOM). The renderer lacks proper sanitization measures, such as DOMPurify, and there is no Content Security Policy (CSP) implemented on the web interface. This vulnerability enables an attacker to control the underlying code execution during a chat session by exploiting HTML injection, potentially leading to unauthorized JavaScript execution on the local host environment. This issue has been addressed in version 1.1.10.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
opencode < 1.1.10
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
