Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in OpenCode Studio allows unauthenticated remote attackers to access sensitive files and delete user data. This issue arises from missing authentication on specific API endpoints, enabling unauthorized users to retrieve intermediate job artifacts and manipulate video content.
- Unauthorized access to user files and data.
- Critical system exposure without any credentials.
- Confirm relevance and potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by directly accessing specific API endpoints over the network without needing any credentials. This exposure allows them to read sensitive temporary files or media artifacts created by other users, and potentially delete video content.
- No authentication required.
- Direct access to API endpoints.
- Sensitive file and video data exposed.
Live Threat
Current exploitation, exposure, and threat context
Unauthenticated attackers could access and delete arbitrary files within the temp and static/music directories. This could occur when specific API endpoints are directly accessed, potentially exposing intermediate audio, video artifacts, and subtitles belonging to other users' jobs.
- Intermediate job artifacts at risk.
- Direct API access could expose files.
- Unauthorized data retrieval and deletion.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in OpenCode Studio likely falls under the responsibility of application owners and platform teams, as it affects core API functionalities for file and media processing. The immediate first step is to inventory all instances of OpenCode Studio, confirm their accessibility and business criticality, and identify the specific application or service owners. Once identified, a risk-based remediation plan should be developed, prioritizing critical and exposed systems.
- Identify accountable application owners.
- Verify external accessibility and impact.
- Plan remediation based on risk.