anomalyco / anomalyco/opencode

Please redact more in opencode shared sessions. Huge potential mass RCE risk.

Open
#48,305 1 comment 0 reactions 1 assignee View on GitHub

@neriousy is already working on this.

Since Sep 10, 2026.

2.0
Dominant language
TypeScript
Stars
209k
Forks
27.5k
Avg merge
7h 2m
Merged PRs (30d)
384

Description

Description

Opencode shared sessions exposes WAYY too much stuff. It exposes what the model writes, model output, and tool execution. full file path and everything
Also i found atleast 2 API keys while reading thru my friend's shared sessions, and its not redacted?? Values and tokens arent redacted... I think thats a little bit concerning no? this could lead to a lot of potential risks... also on https://github.com/anomalyco/opencode/issues

people post a lot of shared sessions there... this is a privacy concern.

People's address, gmails, personal credentials could be leaked.

Image

And by the way.. In this session the model exposes a firecrawl API key, and an openrouter API key. Please fix this

Plugins

None.

OpenCode version

v0.0.0-beta-19425

Steps to reproduce

You can just inspect any shared session and look for API's ...

Screenshot and/or share link

No response

Operating System

Windows 11

Terminal

Windows terminal

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.