Futures
Access hundreds of perpetual contracts
TradFi
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Futures Kickoff
Get prepared for your futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to experience risk-free trading
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Launchpad
Be early to the next big token project
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
OpenCode recently exposed a serious security issue. Cloudflare security researchers discovered that a certain parameter supported by the web frontend is at risk of being abused.
Specifically, attackers can use this parameter to point to malicious servers. Then, by forging Markdown sessions and embedding malicious scripts within them, they can trick users into clicking related links. Once users fall for it, attackers can execute arbitrary commands on the user's computer via the terminal API. This type of attack is quite covert and poses significant risks to developers.
The good news is that the official team has quickly released a fix. The main measures include disabling this problematic parameter and strengthening the Content Security Policy (CSP) to prevent malicious scripts from loading. If you're using related tools, it is recommended to update to the latest version promptly. Security patches like these should not be delayed.