| ▲ | ekidd a day ago | |||||||
It is a pretty catastrophically dumb CVE, of the sort that makes me not want to allow OpenCode anywhere near any of my machines in the future. It was basically "RCE as a service", not some subtle bug. Personally, I run pi-agent in a custom sandbox based on bwrap, with an internet proxy. This mostly limits the blast radius to one source tree and one git checkout. And I don't give it push/pull permission. Local models are fun in a "closely supervised but slightly clueless minion" sort of way. | ||||||||
| ▲ | bel8 a day ago | parent [-] | |||||||
I too love and use pi agent. But all of these agents have or had "dumb" security issues: https://github.com/anthropics/claude-code/security/advisorie... You probably know that since you run pi inside https://github.com/containers/bubblewrap. | ||||||||
| ||||||||