A vulnerability marked as problematic has been reported in Vercel @ai-sdk and harness-opencode up to 1.0.28. The impacted element is an unknown function of the file host-tool-mcp.mjs of the component Relay. The manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-64651. The attack must be carried out locally. There is no available exploit.