Unauthenticated File Access in OpenCode Studio by Microck

⚠️ CVE-Referenzen: CVE-2026-69110
Microck - Opencode-studio - CRITICAL - CVE-2026-69110. OpenCode Studio, prior to version 2.4.4, exhibits a missing authentication vulnerability. This flaw enables unauthorized remote attackers to access sensitive files within the temp and static/music directories by leveraging the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Additionally, attackers can manipulate the system by deleting video content using the unauthenticated DELETE /api/short-video/:videoId endpoint. This vulnerability poses a significant security risk, allowing the exploitation of user data and system integrity. BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io