Hazard Lab

Hazard Lab

Open Policy Agent (OPA) v0.60.0 - Local File Inclusion Vulnerability

Reza's avatar
Reza
Dec 21, 2025
∙ Paid

Severity: High

Vulnerability Type: Local File Inclusion (LFI)

Affected System: Open Policy Agent (OPA) v0.60.0

Open Policy Agent (OPA) is an open-source, general-purpose policy engine that enables fine-grained, context-aware policy enforcement across the entire stack. A critical security vulnerability has been identified in OPA version 0.60.0, allowing an attacker to perform Local File Inclusion (LFI) attacks through the opa parse command, leading to unauthorized access to sensitive files on the host system.

User's avatar

Continue reading this post for free, courtesy of Reza.

Or purchase a paid subscription.
© 2026 Reza · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture