Index › ai › opencode opencode 1 tool · 1 release line Open-source, provider-neutral agentic coding CLI. Every tool here carries the same sandbox boundary. $ boks opencode ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 1.18.23 stable 2026-08-25 81 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect all share one boundary Tool Capabilities Seccomp Findings Image Description ▸ opencode netnomountrorw default C1H26M45L9 opencode Open-source, provider-neutral agentic coding CLI ▸ showing opencode from opencode@latest → 1.18.23 stable Findings C1H26M45L9 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description GHSA-mv8w-475r-vwqw ↗ C 9.8 seroval seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization GHSA-mwp4-54f8-5fhr ↗ H 7.7 ip-address ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-23hp-3jrh-7fpw ↗ H 7.5 tar node-tar: Decompression/parse DoS via unlimited input GHSA-2m8v-j782-fhvr ↗ H 7.5 socket.io-parser Socket.IO: Zero-attachment Memory Exhaustion GHSA-38rv-x7px-6hhq ↗ H 7.5 undici undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-3j22-8qj3-26mx ↗ H 7.5 seroval Seroval affected by Denial of Service via Deeply Nested Objects GHSA-3rxj-6cgf-8cfw ↗ H 7.5 seroval seroval Affected by Remote Code Execution via JSON Deserialization GHSA-4c8g-83qw-93j6 ↗ H 7.5 fast-uri fast-uri vulnerable to host confusion via failed IDN canonicalization GHSA-52cp-r559-cp3m ↗ H 7.5 js-yaml js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-5p4m-2wfm-xmqj ↗ H 7.5 js-yaml JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-66fc-rw6m-c2q6 ↗ H 7.5 seroval Seroval affected by Denial of Service via Array serialization GHSA-7p8r-x3mc-p8w7 ↗ H 7.5 fast-uri fast-uri vulnerable to host confusion via backslash authority introducer GHSA-8x88-c5mf-7j5w ↗ H 7.5 tar node-tar: Negative tar entry size causes infinite loop in archive replace GHSA-96hv-2xvq-fx4p ↗ H 7.5 ws ws: Memory exhaustion DoS from tiny fragments and data chunks GHSA-c96f-x56v-gq3h ↗ H 7.5 find-my-way find-my-way: DDoS with HTTP2 GHSA-hx9m-jf43-8ffr ↗ H 7.5 seroval seroval affected by Denial of Service via RegExp serialization GHSA-mh99-v99m-4gvg ↗ H 7.5 brace-expansion brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-r292-9mhp-454m ↗ H 7.5 tar node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection GHSA-rgw5-rvv9-x895 ↗ H 7.5 brace-expansion brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-v2hh-gcrm-f6hx ↗ H 7.5 fast-uri fast-uri vulnerable to host confusion via literal backslash authority delimiter GHSA-v9p9-hfj2-hcw8 ↗ H 7.5 undici Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation GHSA-vrm6-8vpv-qv8q ↗ H 7.5 undici Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression GHSA-vxpw-j846-p89q ↗ H 7.5 undici undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-4cwx-7wf7-3272 ↗ H 7.4 undici undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-vmh5-mc38-953g ↗ H 7.4 undici undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-hj76-42vx-jwp4 ↗ H 7.3 seroval seroval Affected by Prototype Pollution via JSON Deserialization GHSA-88fw-hqm2-52qc ↗ H 7.1 hono hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard GHSA-22jq-vg5j-6vgg ↗ M 6.9 ip-address ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks GHSA-4xrf-jv44-h6hh ↗ M 6.9 ip-address ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks GHSA-h8r8-wccr-v5f2 ↗ M 6.9 dompurify DOMPurify is vulnerable to mutation-XSS via Re-Contextualization GHSA-v9jr-rg53-9pgp ↗ M 6.9 dompurify DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback GHSA-vmf3-w455-68vh ↗ M 6.9 tar node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) GHSA-crv5-9vww-q3g8 ↗ M 6.8 dompurify DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode GHSA-2mjp-6q6p-2qxm ↗ M 6.5 undici Undici has an HTTP Request/Response Smuggling issue GHSA-hvrm-45r6-mjfj ↗ M 6.5 hono hono/jsx does not isolate context per request, leading to cross-request data disclosure GHSA-rv63-4mwf-qqc2 ↗ M 6.5 hono hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` GHSA-76mc-f452-cxcm ↗ M 6.1 dompurify DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` GHSA-hpcv-96wg-7vj8 ↗ M 6.1 dompurify DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks GHSA-r47g-fvhr-h676 ↗ M 6.1 dompurify DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM GHSA-v2wj-7wpq-c8vv ↗ M 6.1 dompurify DOMPurify contains a Cross-site Scripting vulnerability GHSA-w62v-xxxg-mg59 ↗ M 6.1 hono Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility GHSA-x4vx-rjvf-j5p4 ↗ M 6.1 dompurify DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects GHSA-h7mw-gpvr-xq4m ↗ M 6.0 dompurify DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix) GHSA-frvp-7c67-39w9 ↗ M 5.9 @hono/node-server Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) GHSA-g9mf-h72j-4rw9 ↗ M 5.9 undici Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion GHSA-jr45-8vmc-qm54 ↗ M 5.9 undici undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-p88m-4jfj-68fv ↗ M 5.9 undici undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-pr7r-676h-xcf6 ↗ M 5.9 undici undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-wwfh-h76j-fc44 ↗ M 5.9 hono hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) GHSA-39q2-94rc-95cp ↗ M 5.3 dompurify DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation GHSA-3jxr-9vmj-r5cp ↗ M 5.3 brace-expansion brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-54fx-42gc-7vw4 ↗ M 5.3 hono Hono: Algorithmic Complexity DoS in Language Middleware GHSA-8988-4f7v-96qf ↗ M 5.3 @opentelemetry/core OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation GHSA-8j4g-w8fx-2239 ↗ M 5.3 hono Hono: ReDoS in CORS middleware via Access-Control-Request-Headers GHSA-cj63-jhhr-wcxv ↗ M 5.3 dompurify DOMPurify USE_PROFILES prototype pollution allows event handlers GHSA-cjmm-f4jc-qw8r ↗ M 5.3 dompurify DOMPurify ADD_ATTR predicate skips URI validation GHSA-f38q-mgvj-vph7 ↗ M 5.3 protobufjs protobufjs : Schema-derived names can shadow runtime-significant properties GHSA-gvwx-54wh-qm9j ↗ M 5.3 tar node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records GHSA-h67p-54hq-rp68 ↗ M 5.3 js-yaml JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-j3f2-48v5-ccww ↗ M 5.3 protobufjs protobufjs: Denial of Service via infinite loop in .proto option parsing GHSA-j6c9-x7qj-28xf ↗ M 5.3 hono hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice GHSA-w8wr-v893-vjvp ↗ M 5.3 tar node-tar: Process crash via PAX numeric path type confusion GHSA-55q2-fjhq-7xh7 ↗ M 5.1 dompurify DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS GHSA-cmwh-pvxp-8882 ↗ M 5.1 dompurify DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch) GHSA-rp9w-3fw7-7cwq ↗ M 5.1 dompurify DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content GHSA-8xcm-r25x-g524 ↗ M 4.8 undici undici vulnerable to downstream response desynchronization via retry interceptor GHSA-f23p-vx2j-j53r ↗ M 4.8 hono Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure GHSA-v3r7-h72x-cjcm ↗ M 4.8 undici undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-wgpf-jwqj-8h8p ↗ M 4.8 hono hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest GHSA-xgm2-5f3f-mvvc ↗ M 4.8 hono Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication GHSA-4992-7rv2-5pvq ↗ M 4.6 undici Undici has CRLF Injection in undici via `upgrade` option GHSA-m8rv-5g2x-5cg5 ↗ M 4.2 undici undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-35p6-xmwp-9g52 ↗ L 3.7 undici undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-79qm-7rj5-m7r9 ↗ L 3.7 hono Hono: Proxy Helper does not remove response headers listed in the `Connection` header GHSA-g8m3-5g58-fq7m ↗ L 3.7 undici undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-v422-hmwv-36x6 ↗ L 3.7 body-parser body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement GHSA-4x5r-pxfx-6jf8 ↗ L 3.2 @babel/core @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-73rr-hh4g-fpgx ↗ L 2.7 diff jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch GHSA-c2j3-45gr-mqc4 ↗ L 2.1 dompurify DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. GHSA-vxr8-fq34-vvx9 ↗ L 2.1 dompurify DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output GHSA-gvmj-g25r-r7wr ↗ L 2.0 dompurify DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes These are the findings of opencode, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding. Composition default + bash, coreutils, diffutils, env, findutils, gawk, git, grep, rg, sed runtime none — self-contained composes bash, coreutils, diffutils, env, findutils, gawk, git, grep, rg, sed Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/boks-sh/opencode:1.18.23 digest sha256:60a4…24c2 copy platforms amd64 sha256:6f5a…5dc6 copy arm64 sha256:f548…15df copy size 185 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-25 Sandbox boundary opencode capabilities netnomountrorw Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted ~/.config/opencode · writable ~/.local/share/opencode · writable ~/.local/state/opencode · writable ~/.cache/opencode · writable env passed through 62 forwarded AICORE_SERVICE_KEYAI_GATEWAY_API_KEYANTHROPIC_*AWS_BEARER_TOKEN_BEDROCKAWS_DEFAULT_REGIONAWS_PROFILEAWS_REGIONAZURE_API_KEYAZURE_COGNITIVE_SERVICES_API_KEYAZURE_COGNITIVE_SERVICES_RESOURCE_NAMEAZURE_RESOURCE_NAMEBASETEN_API_KEYCEREBRAS_API_KEYCF_AIG_TOKENCLOUDFLARE_ACCOUNT_IDCLOUDFLARE_API_KEYCLOUDFLARE_API_TOKENCLOUDFLARE_GATEWAY_IDDASHSCOPE_API_KEYDATABRICKS_HOSTDATABRICKS_TOKENDEEPINFRA_API_KEYDEEPSEEK_API_KEYFIREWORKS_API_KEYGEMINI_API_KEYGITLAB_TOKENGOOGLE_API_KEYGOOGLE_CLOUD_LOCATIONGOOGLE_CLOUD_PROJECTGOOGLE_GENERATIVE_AI_API_KEYGOOGLE_VERTEX_LOCATIONGOOGLE_VERTEX_PROJECTGROQ_API_KEYHF_TOKENHTTPS_PROXYHTTP_PROXYLMSTUDIO_API_KEYMISTRAL_API_KEYMOONSHOT_API_KEYNO_PROXYNVIDIA_API_KEYOPENAI_*OPENCODE_API_KEYOPENCODE_DISABLE_AUTOUPDATEOPENCODE_DISABLE_LSP_DOWNLOADOPENCODE_SERVER_PASSWORDOPENCODE_SERVER_USERNAMEOPENROUTER_*OTEL_EXPORTER_OTLP_ENDPOINTOTEL_EXPORTER_OTLP_HEADERSOTEL_RESOURCE_ATTRIBUTESPERPLEXITY_API_KEYSNOWFLAKE_ACCOUNTSNOWFLAKE_CORTEX_PATSNOWFLAKE_CORTEX_TOKENTOGETHER_API_KEYVENICE_API_KEYXAI_API_KEYZHIPU_API_KEYhttp_proxyhttps_proxyno_proxy Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by boks 2 set OPENCODE_DISABLE_AUTOUPDATEOPENCODE_DISABLE_LSP_DOWNLOAD per-subcommand grants differ export + ro − netrw models + ro − rw providers + ro − rw stats + ro − netrw uninstall + nomount − netrw upgrade + nomount − rw Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Where it needs less, boks takes it away there too. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-25 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 81 findings across this project at latest. Counted once per advisory across every image the project builds.