PT-2026-67507 · Ouroboros · Ouroboros

CVE-2026-66065

·

Published

2026-06-19

·

Updated

2026-08-03

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ouroboros versions prior to 0.42.1
Description An incomplete denylist allows a malicious cloned repository to achieve arbitrary command execution by providing a .env file that is automatically loaded during import without a review step. This occurs because several execution-routing keys were omitted from the UNTRUSTED ENV DENYLIST. Specifically, the backend config-home and MCP/plugin roots can bypass the approval gate by redirecting the nested agent, MCP servers, and plugin roster to an attacker-controlled configuration. Additionally, other variables can re-enable blocked local transports, replace sub-agent prompts, switch backends, and lower tool approval classes, which further weakens the approval gate.
Recommendations Update to version 0.42.1.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66065
GHSA-JV2H-4P9V-WF5W

Affected Products

Ouroboros