anomalyco / anomalyco/opencode
Please redact more in opencode shared sessions. Huge potential mass RCE risk.
@neriousy is already working on this.
Since Sep 10, 2026.
- Dominant language
- TypeScript
- Stars
- 209k
- Forks
- 27.5k
- Avg merge
- 7h 2m
- Merged PRs (30d)
- 384
Description
Description
Opencode shared sessions exposes WAYY too much stuff. It exposes what the model writes, model output, and tool execution. full file path and everything
Also i found atleast 2 API keys while reading thru my friend's shared sessions, and its not redacted?? Values and tokens arent redacted... I think thats a little bit concerning no? this could lead to a lot of potential risks... also on https://github.com/anomalyco/opencode/issues
people post a lot of shared sessions there... this is a privacy concern.
People's address, gmails, personal credentials could be leaked.
And by the way.. In this session the model exposes a firecrawl API key, and an openrouter API key. Please fix this
Plugins
None.
OpenCode version
v0.0.0-beta-19425
Steps to reproduce
You can just inspect any shared session and look for API's ...
Screenshot and/or share link
No response
Operating System
Windows 11
Terminal
Windows terminal
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.