


Perceptive Security
SOC/SIEM Consultancy

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the tem…
Published:
4 August 2026 at 00:00:00
Alert date:
4 August 2026 at 19:02:19
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Data Breach & Exfiltration
OpenCode Studio versions before 2.4.4 contain a missing authentication vulnerability affecting multiple API endpoints. Unauthenticated remote attackers can read arbitrary files from the temp and static/music directories via GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can access intermediate audio, video artifacts, and subtitles belonging to other users. Additionally, the unauthenticated DELETE /api/short-video/:videoId endpoint allows any attacker to delete videos by ID. The vulnerability exposes sensitive user job artifacts and enables destructive actions without any credentials. A fix was released in version 2.4.4, with the patch available via a GitHub commit. The issue was tracked and resolved through GitHub issues and pull requests.
Technical details
Mitigation steps:
Affected products:
OpenCode Studio
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69110
https://github.com/Microck/opencode-studio/commit/1f4d7a7f52beb43105d345b26fd0c0ffc2bf0004
https://github.com/Microck/opencode-studio/issues/54
https://github.com/Microck/opencode-studio/pull/55
https://github.com/Microck/opencode-studio/releases/tag/v2.4.4
https://www.vulncheck.com/advisories/opencode-studio-unauthenticated-file-read-via-api-tmp-and-api-music
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
