Wu Shuo learned that OpenCode developer thdxr disclosed that a serious security vulnerability was fixed on Friday. Cloudflare security researchers discovered that parameters supported by the web frontend could be exploited to point to malicious servers. Through a fake Markdown session containing inline scripts, users are induced to click links, which then allows arbitrary commands to be executed on the computer via the terminal API. The official fix has been released, including disabling the parameter, adding CSP headers, and enforcing password verification. DeFiLlama founder 0xngmi commented that previously Cursor also exposed a vulnerability that allowed arbitrary code to run on any computer with the software installed. He speculated that the pressure from the AI race to deliver products has led to security issues being overlooked.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Wu Shuo learned that OpenCode developer thdxr disclosed that a serious security vulnerability was fixed on Friday. Cloudflare security researchers discovered that parameters supported by the web frontend could be exploited to point to malicious servers. Through a fake Markdown session containing inline scripts, users are induced to click links, which then allows arbitrary commands to be executed on the computer via the terminal API. The official fix has been released, including disabling the parameter, adding CSP headers, and enforcing password verification. DeFiLlama founder 0xngmi commented that previously Cursor also exposed a vulnerability that allowed arbitrary code to run on any computer with the software installed. He speculated that the pressure from the AI race to deliver products has led to security issues being overlooked.