Critical CVE-2026-88899 Vulnerability in cve-2026-88899 npm Package
- Severity
- CRITICAL
- CVSS
- 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Affected component
- cve-2026-88899 (npm)
- Affected versions
- >= v0.30.0, <= v0.30.0 or >= v0.29.1, <= v0.29.1 or >= v0.29.0, <= v0.29.0 or >= v0.28.0, <= v0.28.0 or >= v0.27.1, <= v0.27.1 or >= v0.27.0, <= v0.27.0 or >= v0.23.0, <= v0.23.0 or >= v0.26.0, <= v0.26.0 or >= v0.25.0, <= v0.25.0 or >= v0.24.1, <= v0.24.1 or >= v0.24.0, <= v0.24.0 or >= v0.22.2, <= v0.22.2 or >= v0.22.1, <= v0.22.1 or >= v0.22.0, <= v0.22.0 or >= v0.21.0, <= v0.21.0 or >= v0.20.5, <= v0.20.5 or >= v0.20.4, <= v0.20.4 or >= v0.20.3, <= v0.20.3 or >= v0.20.2, <= v0.20.2 or >= v0.20.1, <= v0.20.1 or >= v0.20.0, <= v0.20.0 or >= v0.19.2, <= v0.19.2 or >= v0.19.1, <= v0.19.1 or >= v0.19.0, <= v0.19.0 or >= v0.18.4, <= v0.18.4 or >= v0.18.3, <= v0.18.3 or >= v0.18.2, <= v0.18.2 or >= v0.18.1, <= v0.18.1 or >= v0.18.0, <= v0.18.0 or >= v0.17.1, <= v0.17.1 or >= v0.17.0, <= v0.17.0 or >= v0.16.3, <= v0.16.3 or >= v0.16.2, <= v0.16.2 or >= v0.16.1, <= v0.16.1 or >= v0.16.0, <= v0.16.0 or >= v0.15.3, <= v0.15.3 or >= v0.15.2, <= v0.15.2 or >= v0.15.1, <= v0.15.1 or >= v0.15.0, <= v0.15.0 or >= v0.12.4, <= v0.12.4 or >= v0.12.3, <= v0.12.3 or >= v0.12.2, <= v0.12.2 or >= v0.12.1, <= v0.12.1 or >= v0.12.0, <= v0.12.0 or >= v0.11.4, <= v0.11.4 or >= v0.11.3, <= v0.11.3 or >= v0.11.2, <= v0.11.2 or >= v0.11.1, <= v0.11.1 or >= v0.11.0, <= v0.11.0 or >= v0.10.6, <= v0.10.6 or >= v0.10.5, <= v0.10.5 or >= v0.10.4, <= v0.10.4 or >= v0.10.3, <= v0.10.3 or >= v0.10.2, <= v0.10.2 or >= v0.10.1, <= v0.10.1 or >= v0.10.0, <= v0.10.0 or >= v0.9.0, <= v0.9.0 or >= v0.8.9, <= v0.8.9 or >= v0.8.8, <= v0.8.8 or >= v0.8.7, <= v0.8.7 or >= v0.8.6, <= v0.8.6 or >= v0.8.5, <= v0.8.5 or >= v0.8.4, <= v0.8.4 or >= v0.8.3, <= v0.8.3 or >= v0.8.2, <= v0.8.2 or >= v0.8.1, <= v0.8.1 or >= v0.8.0, <= v0.8.0 or >= v0.7.0, <= v0.7.0 or >= v0.6.0, <= v0.6.0 or >= v0.5.0, <= v0.5.0 or >= v0.4.0, <= v0.4.0 or >= v0.3.1, <= v0.3.1 or >= v0.3.0, <= v0.3.0 or >= v0.2.1, <= v0.2.1 or >= v0.2.0, <= v0.2.0 or >= v0.1.8, <= v0.1.8 or >= v0.1.7, <= v0.1.7 or >= v0.1.6, <= v0.1.6 or >= v0.1.5, <= v0.1.5 or >= v0.1.4, <= v0.1.4 or >= v0.1.3, <= v0.1.3 or >= v0.1.2, <= v0.1.2 or >= v0.1.1, <= v0.1.1
- Patched version
- 0.31.0
An early warning has been issued for a critical vulnerability in the cve-2026-88899 npm package. Users of affected versions are advised to upgrade immediately.
What happened
Versions of the cve-2026-88899 npm package before 0.31.0 reportedly fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. This vulnerability allows remote attackers to supply arbitrary directory paths and execute file operations outside the project root on the host system.
The vulnerability, tracked as CVE-2026-88899, has a CVSS score of 9.8, indicating a critical severity level. The vulnerability is not yet reported to be exploited in the wild.
What to do about it
- Upgrade to cve-2026-88899@0.31.0 or later to mitigate the risk.
- Review your project dependencies to identify any use of the affected package versions.
- If you are unable to upgrade immediately, consider implementing additional security measures to limit exposure.
- Monitor the primary sources for updates on the vulnerability and any further patches.
How 0Day would have caught this
cve-2026-88899 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using any version of the cve-2026-88899 npm package before 0.31.0.
What should I do right now?
Upgrade to cve-2026-88899@0.31.0 or later as soon as possible.
Has this been exploited in the wild?
There are no reports of this vulnerability being exploited in the wild at this time.