OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionally delete any video by ID through the unauthenticated DELETE /api/short-video/:videoId endpoint.
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 3.1 | Primary | cve.org | 9.1 | — | — |
| 3.1 | Primary | NVD | 9.1 | 3.9 | 5.2 |
| 4.0 | Primary | cve.org | 9.3 | — | — |
| 4.0 | Secondary | ENISA EUVD | 9.3 | — | — |
| 4.0 | Secondary | NVD | 9.3 | — | — |