PT-2026-67507 · Ouroboros · Ouroboros
CVE-2026-66065
·
Published
2026-06-19
·
Updated
2026-08-03
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ouroboros versions prior to 0.42.1
Description
An incomplete denylist allows a malicious cloned repository to achieve arbitrary command execution by providing a
.env file that is automatically loaded during import without a review step. This occurs because several execution-routing keys were omitted from the UNTRUSTED ENV DENYLIST. Specifically, the backend config-home and MCP/plugin roots can bypass the approval gate by redirecting the nested agent, MCP servers, and plugin roster to an attacker-controlled configuration. Additionally, other variables can re-enable blocked local transports, replace sub-agent prompts, switch backends, and lower tool approval classes, which further weakens the approval gate.Recommendations
Update to version 0.42.1.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ouroboros