boks Index
Docs Releases

opencode

1 tool · 1 release line

Open-source, provider-neutral agentic coding CLI. Every tool here carries the same sandbox boundary.

boks opencode

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing opencode from opencode@latest → 1.18.23 stable

Findings

C1H26M45L9

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
GHSA-mv8w-475r-vwqw ↗ C 9.8 seroval seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
GHSA-mwp4-54f8-5fhr ↗ H 7.7 ip-address ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
GHSA-23hp-3jrh-7fpw ↗ H 7.5 tar node-tar: Decompression/parse DoS via unlimited input
GHSA-2m8v-j782-fhvr ↗ H 7.5 socket.io-parser Socket.IO: Zero-attachment Memory Exhaustion
GHSA-38rv-x7px-6hhq ↗ H 7.5 undici undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
GHSA-3j22-8qj3-26mx ↗ H 7.5 seroval Seroval affected by Denial of Service via Deeply Nested Objects
GHSA-3rxj-6cgf-8cfw ↗ H 7.5 seroval seroval Affected by Remote Code Execution via JSON Deserialization
GHSA-4c8g-83qw-93j6 ↗ H 7.5 fast-uri fast-uri vulnerable to host confusion via failed IDN canonicalization
GHSA-52cp-r559-cp3m ↗ H 7.5 js-yaml js-yaml: YAML merge-key chains can force quadratic CPU consumption
GHSA-5p4m-2wfm-xmqj ↗ H 7.5 js-yaml JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
GHSA-66fc-rw6m-c2q6 ↗ H 7.5 seroval Seroval affected by Denial of Service via Array serialization
GHSA-7p8r-x3mc-p8w7 ↗ H 7.5 fast-uri fast-uri vulnerable to host confusion via backslash authority introducer
GHSA-8x88-c5mf-7j5w ↗ H 7.5 tar node-tar: Negative tar entry size causes infinite loop in archive replace
GHSA-96hv-2xvq-fx4p ↗ H 7.5 ws ws: Memory exhaustion DoS from tiny fragments and data chunks
GHSA-c96f-x56v-gq3h ↗ H 7.5 find-my-way find-my-way: DDoS with HTTP2
GHSA-hx9m-jf43-8ffr ↗ H 7.5 seroval seroval affected by Denial of Service via RegExp serialization
GHSA-mh99-v99m-4gvg ↗ H 7.5 brace-expansion brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-r292-9mhp-454m ↗ H 7.5 tar node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
GHSA-rgw5-rvv9-x895 ↗ H 7.5 brace-expansion brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
GHSA-v2hh-gcrm-f6hx ↗ H 7.5 fast-uri fast-uri vulnerable to host confusion via literal backslash authority delimiter
GHSA-v9p9-hfj2-hcw8 ↗ H 7.5 undici Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
GHSA-vrm6-8vpv-qv8q ↗ H 7.5 undici Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
GHSA-vxpw-j846-p89q ↗ H 7.5 undici undici WebSocket client vulnerable to denial of service via fragment count bypass
GHSA-4cwx-7wf7-3272 ↗ H 7.4 undici undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
GHSA-vmh5-mc38-953g ↗ H 7.4 undici undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
GHSA-hj76-42vx-jwp4 ↗ H 7.3 seroval seroval Affected by Prototype Pollution via JSON Deserialization
GHSA-88fw-hqm2-52qc ↗ H 7.1 hono hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
GHSA-22jq-vg5j-6vgg ↗ M 6.9 ip-address ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
GHSA-4xrf-jv44-h6hh ↗ M 6.9 ip-address ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
GHSA-h8r8-wccr-v5f2 ↗ M 6.9 dompurify DOMPurify is vulnerable to mutation-XSS via Re-Contextualization
GHSA-v9jr-rg53-9pgp ↗ M 6.9 dompurify DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
GHSA-vmf3-w455-68vh ↗ M 6.9 tar node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
GHSA-crv5-9vww-q3g8 ↗ M 6.8 dompurify DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode
GHSA-2mjp-6q6p-2qxm ↗ M 6.5 undici Undici has an HTTP Request/Response Smuggling issue
GHSA-hvrm-45r6-mjfj ↗ M 6.5 hono hono/jsx does not isolate context per request, leading to cross-request data disclosure
GHSA-rv63-4mwf-qqc2 ↗ M 6.5 hono hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
GHSA-76mc-f452-cxcm ↗ M 6.1 dompurify DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`
GHSA-hpcv-96wg-7vj8 ↗ M 6.1 dompurify DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
GHSA-r47g-fvhr-h676 ↗ M 6.1 dompurify DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
GHSA-v2wj-7wpq-c8vv ↗ M 6.1 dompurify DOMPurify contains a Cross-site Scripting vulnerability
GHSA-w62v-xxxg-mg59 ↗ M 6.1 hono Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
GHSA-x4vx-rjvf-j5p4 ↗ M 6.1 dompurify DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
GHSA-h7mw-gpvr-xq4m ↗ M 6.0 dompurify DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)
GHSA-frvp-7c67-39w9 ↗ M 5.9 @hono/node-server Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
GHSA-g9mf-h72j-4rw9 ↗ M 5.9 undici Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
GHSA-jr45-8vmc-qm54 ↗ M 5.9 undici undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
GHSA-p88m-4jfj-68fv ↗ M 5.9 undici undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
GHSA-pr7r-676h-xcf6 ↗ M 5.9 undici undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
GHSA-wwfh-h76j-fc44 ↗ M 5.9 hono hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
GHSA-39q2-94rc-95cp ↗ M 5.3 dompurify DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
GHSA-3jxr-9vmj-r5cp ↗ M 5.3 brace-expansion brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
GHSA-54fx-42gc-7vw4 ↗ M 5.3 hono Hono: Algorithmic Complexity DoS in Language Middleware
GHSA-8988-4f7v-96qf ↗ M 5.3 @opentelemetry/core OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
GHSA-8j4g-w8fx-2239 ↗ M 5.3 hono Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
GHSA-cj63-jhhr-wcxv ↗ M 5.3 dompurify DOMPurify USE_PROFILES prototype pollution allows event handlers
GHSA-cjmm-f4jc-qw8r ↗ M 5.3 dompurify DOMPurify ADD_ATTR predicate skips URI validation
GHSA-f38q-mgvj-vph7 ↗ M 5.3 protobufjs protobufjs : Schema-derived names can shadow runtime-significant properties
GHSA-gvwx-54wh-qm9j ↗ M 5.3 tar node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
GHSA-h67p-54hq-rp68 ↗ M 5.3 js-yaml JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
GHSA-j3f2-48v5-ccww ↗ M 5.3 protobufjs protobufjs: Denial of Service via infinite loop in .proto option parsing
GHSA-j6c9-x7qj-28xf ↗ M 5.3 hono hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
GHSA-w8wr-v893-vjvp ↗ M 5.3 tar node-tar: Process crash via PAX numeric path type confusion
GHSA-55q2-fjhq-7xh7 ↗ M 5.1 dompurify DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
GHSA-cmwh-pvxp-8882 ↗ M 5.1 dompurify DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
GHSA-rp9w-3fw7-7cwq ↗ M 5.1 dompurify DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
GHSA-8xcm-r25x-g524 ↗ M 4.8 undici undici vulnerable to downstream response desynchronization via retry interceptor
GHSA-f23p-vx2j-j53r ↗ M 4.8 hono Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
GHSA-v3r7-h72x-cjcm ↗ M 4.8 undici undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
GHSA-wgpf-jwqj-8h8p ↗ M 4.8 hono hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
GHSA-xgm2-5f3f-mvvc ↗ M 4.8 hono Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
GHSA-4992-7rv2-5pvq ↗ M 4.6 undici Undici has CRLF Injection in undici via `upgrade` option
GHSA-m8rv-5g2x-5cg5 ↗ M 4.2 undici undici vulnerable to CRLF Injection via blob-like body 'type' property
GHSA-35p6-xmwp-9g52 ↗ L 3.7 undici undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
GHSA-79qm-7rj5-m7r9 ↗ L 3.7 hono Hono: Proxy Helper does not remove response headers listed in the `Connection` header
GHSA-g8m3-5g58-fq7m ↗ L 3.7 undici undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
GHSA-v422-hmwv-36x6 ↗ L 3.7 body-parser body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
GHSA-4x5r-pxfx-6jf8 ↗ L 3.2 @babel/core @babel/core: Arbitrary File Read via sourceMappingURL Comment
GHSA-73rr-hh4g-fpgx ↗ L 2.7 diff jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
GHSA-c2j3-45gr-mqc4 ↗ L 2.1 dompurify DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
GHSA-vxr8-fq34-vvx9 ↗ L 2.1 dompurify DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output
GHSA-gvmj-g25r-r7wr ↗ L 2.0 dompurify DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes

These are the findings of opencode, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Composition

default + bash, coreutils, diffutils, env, findutils, gawk, git, grep, rg, sed
runtime none — self-contained
composes bash, coreutils, diffutils, env, findutils, gawk, git, grep, rg, sed

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/opencode:1.18.23
digest
platforms
size 185 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

opencode

capabilities

netnomountrorw

Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.config/opencode · writable
  • ~/.local/share/opencode · writable
  • ~/.local/state/opencode · writable
  • ~/.cache/opencode · writable

env passed through

62 forwarded

AICORE_SERVICE_KEYAI_GATEWAY_API_KEYANTHROPIC_*AWS_BEARER_TOKEN_BEDROCKAWS_DEFAULT_REGIONAWS_PROFILEAWS_REGIONAZURE_API_KEYAZURE_COGNITIVE_SERVICES_API_KEYAZURE_COGNITIVE_SERVICES_RESOURCE_NAMEAZURE_RESOURCE_NAMEBASETEN_API_KEYCEREBRAS_API_KEYCF_AIG_TOKENCLOUDFLARE_ACCOUNT_IDCLOUDFLARE_API_KEYCLOUDFLARE_API_TOKENCLOUDFLARE_GATEWAY_IDDASHSCOPE_API_KEYDATABRICKS_HOSTDATABRICKS_TOKENDEEPINFRA_API_KEYDEEPSEEK_API_KEYFIREWORKS_API_KEYGEMINI_API_KEYGITLAB_TOKENGOOGLE_API_KEYGOOGLE_CLOUD_LOCATIONGOOGLE_CLOUD_PROJECTGOOGLE_GENERATIVE_AI_API_KEYGOOGLE_VERTEX_LOCATIONGOOGLE_VERTEX_PROJECTGROQ_API_KEYHF_TOKENHTTPS_PROXYHTTP_PROXYLMSTUDIO_API_KEYMISTRAL_API_KEYMOONSHOT_API_KEYNO_PROXYNVIDIA_API_KEYOPENAI_*OPENCODE_API_KEYOPENCODE_DISABLE_AUTOUPDATEOPENCODE_DISABLE_LSP_DOWNLOADOPENCODE_SERVER_PASSWORDOPENCODE_SERVER_USERNAMEOPENROUTER_*OTEL_EXPORTER_OTLP_ENDPOINTOTEL_EXPORTER_OTLP_HEADERSOTEL_RESOURCE_ATTRIBUTESPERPLEXITY_API_KEYSNOWFLAKE_ACCOUNTSNOWFLAKE_CORTEX_PATSNOWFLAKE_CORTEX_TOKENTOGETHER_API_KEYVENICE_API_KEYXAI_API_KEYZHIPU_API_KEYhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by boks

2 set

OPENCODE_DISABLE_AUTOUPDATEOPENCODE_DISABLE_LSP_DOWNLOAD

per-subcommand

grants differ

export + ro netrw
models + ro rw
providers + ro rw
stats + ro netrw
uninstall + nomount netrw
upgrade + nomount rw

Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Where it needs less, boks takes it away there too.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

81 findings across this project at latest. Counted once per advisory across every image the project builds.