Comment by throw_me_uwu
1 month ago
WTF, they not just made unauthenticated RCE http endpoint, they also helpfully added CORS bypass for it... all in CLI tool? That silently starts http server??
1 month ago
WTF, they not just made unauthenticated RCE http endpoint, they also helpfully added CORS bypass for it... all in CLI tool? That silently starts http server??
Someone tell the AI labs to stop training on tutorial code.
I'm slightly surprised that the CORS policy wasn't just "*" considering how wide open the server itself was.
That's the point, it was!
https://github.com/anomalyco/opencode/commit/7d2d87fa2c44e32...
It seems like it was prior to 1.0.216?
Just run it in a sandbox, bro.
It’s a vibe, bro.