CVE-2026-69110: OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionally delete any video by ID through the unauthenticated DELETE /api/short-video/:videoId endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-69110?
CVE-2026-69110 has a severity rating of critical with a score of 9.1.
How do I fix CVE-2026-69110?
To fix CVE-2026-69110, upgrade OpenCode Studio to version 2.4.4 or later.
What impact does CVE-2026-69110 have?
CVE-2026-69110 allows unauthenticated remote attackers to read arbitrary files, posing significant data exposure risks.
Is CVE-2026-69110 a path traversal vulnerability?
Yes, CVE-2026-69110 is classified as a path traversal vulnerability.
When was CVE-2026-69110 published?
CVE-2026-69110 was published on August 4, 2026.