Any website can trivially run arbitrary code as the current user if OpenCode is installed; that's CVSS ~10.