Comment by throw_me_uwu
3 days ago
WTF, they not just made unauthenticated RCE http endpoint, they also helpfully added CORS bypass for it... all in CLI tool? That silently starts http server??
3 days ago
WTF, they not just made unauthenticated RCE http endpoint, they also helpfully added CORS bypass for it... all in CLI tool? That silently starts http server??
Someone tell the AI labs to stop training on tutorial code.
I'm slightly surprised that the CORS policy wasn't just "*" considering how wide open the server itself was.
That's the point, it was!
https://github.com/anomalyco/opencode/commit/7d2d87fa2c44e32...
It seems like it was prior to 1.0.216?
Just run it in a sandbox, bro.
It’s a vibe, bro.