OpenCode had drive-by RCE via /global/upgrade (fixed in 1.18.22)
Datadog Security Labs disclosed GHSA-632h-h47v-g4x4: OpenCode’s /global/upgrade endpoint accepted a cross-origin text/plain form that installed an attacker npm tarball. Versions 1.14.30–1.18.21 are affected when running opencode serve/web without auth (or with cached basic auth); upgrade to 1.18.22.