CRITICAL
9.8 CVE-2026-88899 Published 10 Sept 2026
Nginx API Endpoint Path Traversal Vulnerability
Worried this affects one of your servers?
Certain versions of Nginx before 0.31.0 have a vulnerability in the /api/opencode proxy endpoint.
Nginx fails to properly validate the 'x-opencode-directory' request header, allowing remote attackers to supply arbitrary directory paths.
This can result in file operations being executed outside the project root on the host system.
Reference: CVE-2026-88899 on NVD
← Back to Security News