Dashboard › opencode › PTY env authorization bypass
01a07f58-e0a9-7c42-8b09-ecf2e6070c18Trap: inheriting the service-manager or client environment looks convenient, but it can leak /home/byk/.opencode/env credentials or let client-controlled values alter execution. Fix: accept no environment or systemd property names from clients; the fixed launcher must call clearenv() and set only HOME, LANG, PATH, SHELL, and TERM before executing /usr/bin/script.