SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-88899

CRITICAL · CVSS 9.8 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Versions prior to 0.31.0 are vulnerable due to improper validation of the x-opencode-directory request header in the /api/opencode proxy endpoint, allowing remote attackers to execute file operations outside the project root. This critical vulnerability poses a significant risk of unauthorized access and potential data compromise on affected systems. Organizations utilizing these versions should prioritize immediate patching to mitigate the threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88899
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%

Original NVD Description

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.