CRITICAL 9.8 CVE-2026-88899 Published 10 Sept 2026

Nginx API Endpoint Path Traversal Vulnerability

Worried this affects one of your servers?

Certain versions of Nginx before 0.31.0 have a vulnerability in the /api/opencode proxy endpoint.

Nginx fails to properly validate the 'x-opencode-directory' request header, allowing remote attackers to supply arbitrary directory paths.

This can result in file operations being executed outside the project root on the host system.

Reference: CVE-2026-88899 on NVD

← Back to Security News