CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-64651: Vercel AI SDK OpenCode Harness Authorization Bypass

August 6, 2026

The @ai-sdk/harness-opencode package through version 1.0.27 allows sandboxed code to invoke host-exposed tools by spoofing the process path. CVSS v4.0 score 6.3. Fixed in version 1.0.28.