5 ms·
hey maintainer here we've done a poor job handling these security reports, usage has grown rapidly and we're overwhelmed with issues we're meeting with some p
by thdxr 9mo ago
hey maintainer here
we've done a poor job handling these security reports, usage has grown rapidly and we're overwhelmed with issues
we're meeting with some people this week to advise us on how to handle this better, get a bug bounty program funded and have some audits done
- digdugdirk 9mo agoI've been curious how this project will grow over time, it seems to have taken the lead as the first open source terminal agent framework/runner, and definitely seems to be growing faster than any organization would/could/should be able to manage. It really seems like the main focus of the project should be in how to organize the work of the project, rather than on the specs/requirements/development of the codebase itself. What are the general recommendations the team has been getting for how to manage the development velocity? And have you looked into various anarchist organizational principles?
- rtaylorgarlock 9mo agoRespect for openness. Good work and good luck.
- Rygian 9mo agoI don't understand what is being encouraged here. Something is seriously wrong when we say "hey, respect!" to a company who develops an unauthenticated RCE feature that should glaringly shine [0] during any internal security analysis, on software that they are licensing in exchange for money [1], and then fumble and drop the ball on security reports when someone does their due diligence for them. If this company wants to earn any respect, they need at least to publish their post-mortem about how their software development practices allowed such a serious issue to reach shipping. This should come as a given, especially seeing that this company already works on software related to security (OpenAuth [2]). [0] https://owasp.org/Top10/2025/ https://owasp.org/Top10/2025/ - https://owasp.org/Top10/2025/A06_2025-Insecure_Design/ https://owasp.org/Top10/2025/A06_2025-Insecure_Design/ - https://owasp.org/Top10/2025/A01_2025-Broken_Access_Control/ https://owasp.org/Top10/2025/A01_2025-Broken_Access_Control/ - https://owasp.org/Top10/2025/A05_2025-Injection/ https://owasp.org/Top10/2025/A05_2025-Injection/ [1] https://opencode.ai/enterprise https://opencode.ai/enterprise [2] https://anoma.ly/ https://anoma.ly/
- GoblinSlayer 9mo agoHonestly RCE here is in the browser. Why the browser executes any code in sight and this code can do anything?
- Rygian 9mo agoIt's called "the world wide web" and it works on the principle that a webpage served by computer A can contain links that point to other pages served by computer B. Whether that principle should have been sustained in the special case of "B = localhost" is a valid question. I think the consensus from the past 40 years has been "yes", probably based on the amount of unknown failure possibilities if the default was reversed to "no".
- GoblinSlayer 9mo agoowasp A01 addresses this: Violation of the principle of least privilege, commonly known as deny by default, where access should only be granted for particular capabilities, roles, or users, but is available to anyone. Indeed, deny by default policy results in unknown failure possibilities, it's inherent to safety.
- pixl97 9mo ago>Violation of the principle of least privilege I completely agree with this, programs are too open most of the time. But, this also brings up a conundrum... Programs that are wide open and insecure typically are very forgiving of user misconfigurations and misunderstandings, so they are the ones that end up widely adopted. Whereas a secure by default application takes much more knowledge to use in most cases, even though they protect the end user better, see less distribution unless forced by some other mechanism such as compliance.
- Cornbilly 9mo agoI’ve noticed this a lot with startup culture. It’s like an unwritten rule to only praise each other because to give honest criticism invites people to do the same to you and too much criticism will halt the gravy train.
- Imustaskforhelp 9mo agoMy original message was more positive but after more looking into context, I am a bit more pessimistic. Now I must admit though that I am little concerned by the fact that the vulnerability reporters tried multiple times to contact you but till no avail. This is not a good look at all and I hope you can fix it asap as you mention I respect dax from the days of SST framework but this is genuinely such a bad look especially when they Reported on 2025-11-17, and multiple "no responses" after repeated attempts to contact the maintainers... Sure they reported the bug now but who knows what could have / might have even been happening as OpenCode was the most famous open source coding agent and surely more cybersec must have watched it, I can see a genuine possibility where something must have been used in the wild as well from my understanding from black hat adversaries I think this means that we should probably run models in gvisor/proper sandboxing efforts. Even right now, we don't know how many more such bugs might persist and can lead to even RCE. Dax, This short attention would make every adversary look for even more bugs / RCE vulnerabilities right now as we speak so you only have a very finite time in my opinion. I hope things can be done as fast as possible now to make OpenCode more safer.
- thdxr 9mo agothe email they found was from a different repo and not monitored. this is ultimately our fault for not having a proper SECURITY.md on our main repository the issue that was reported was fixed as soon as we heard about it - going through the process of learning about the CVE process, etc now and setting everything up correctly. we get 100s of issues reported to us daily across various mediums and we're figuring out how to manage this i can't really say much beyond this is my own inexperience showing
- euazOn 9mo agoI am also baffled at how long this vulnerability was left open, but I’m glad you’re at least making changes to hopefully avoid such mistakes in the future. Just a thought, have you tried any way to triage these reported issues via LLMs, or constantly running an LLM to check the codebase for gaping security holes? Would that be in any way useful? Anyway, thanks for your work on opencode and good luck.
- deleted 9mo ago[deleted]
- heliumtera 9mo agoCongrats on owning this, good job, respect
- shimman 9mo agoIt's hard to not own it when it's publicly disclosed. Maybe save the accolades for when they actually do something and not just say something.
- bopbopbop7 9mo agoWhy not just ask Claude to fix the security issues and make sure they don't happen again?
- Hamuko 9mo agoAnd if you don't have a Claude subscription, you can just ask your friends to fix them via the remote code execution server.
- reactordev 9mo agoThere goes my discord side hustle, offering Claude code through your OpenCode.
- Y_Y 9mo agoTalk about kicking someone while they're down...
- croes 9mo agoWho knows what created the issues in the first place place
- deleted 9mo ago[deleted]
- falloutx 9mo agoIts okay, if you can fix it soon, it should be fine.
- observationist 9mo agoGood luck, and thank you for eating the accountability sandwich and being up front about what you're doing. That's not always easy to do, and it's appreciated!
- Rygian 9mo agoDon't waste your time and money on funding bug bounties or "getting audits done". Your staff will add another big security flaw just the next day, back to square one. Spend that money in reorganizing your management and training your staff so that everyone in your company is onboard with https://owasp.org/Top10/2025/A06_2025-Insecure_Design/ https://owasp.org/Top10/2025/A06_2025-Insecure_Design/ .
- staticassertion 9mo agoIf part of the problem was that no one was responding to a vulnerability report then a bug bounty program would potentially address that.
- liveoneggs 9mo agoyou just get spammed with the same three fake reports over and over
- staticassertion 9mo agoTriage is something that these services provide, exactly to deal with that.
- liveoneggs 9mo agogood try :)
- dionian 9mo agoI don't know much about your product, but I have to say that hearing this kind of blunt communication is really refreshing
- deleted 9mo ago[deleted]
- cryptonector 9mo agoFor one thing spend a lot more time analyzing your code for these bugs. Use expert humans + LLMs to come up with an analysis plan then use humans + LLMs to execute the plan.