TI Mindmap HUB
Threat Intelligence Report

Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4)

📅 September 24, 2026 📰 securitylabs.datadoghq.com 🔍 0 CVE(s) referenced

A content-type confusion in OpenCode’s unauthenticated upgrade API allowed malicious websites to trigger remote code execution via attacker-controlled npm tarballs, affecting versions 1.14.30–1.18.21 before the flaw was fixed in 1.18.22.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle