Junglewise Threat Intelligence

CVE-2026-69110: OpenCode Studio missing authentication in file endpoints

CVE-2026-69110 · Severity: critical · CVSS 9.1 · Published 2026-08-04

Executive brief

OpenCode Studio is a video generation and processing application that exposes file serving endpoints without authentication. Attackers can directly access temporary files, audio artifacts, and video metadata belonging to other users, and delete any video without authorization, potentially exposing sensitive work artifacts and disrupting service availability.

Technical details

OpenCode Studio exposes REST API endpoints (GET /api/tmp/:tmpFile, GET /api/music/:fileName, and DELETE /api/short-video/:videoId) without authentication checks. The vulnerable code directly streams files from the temp and static/music directories without validating session ownership or access rights, allowing any network-connected attacker to enumerate and read arbitrary files within those directories. Attackers can retrieve intermediate audio, video artifacts, subtitles, and metadata from other users' transcoding jobs, and delete videos by guessing or enumerating video IDs. While Express parameter routing prevents classic ../ path traversal to the filesystem root, the core vulnerability stems from missing authentication and per-user file isolation. The fix in version 2.4.4 adds authentication middleware and restricts access to user-owned content.

Affected products

  • Microck OpenCode Studio before 2.4.4

Timeline

  • 2026-07-19: disclosed: Vulnerability reported on GitHub issue #54
  • 2026-08-04: patched: Fix committed in commit 1f4d7a7f52beb43105d345b26fd0c0ffc2bf0004
  • 2026-08-04: advisory: CVE-2026-69110 published to NVD

References