PT-2026-79411 · Omnigent · Omnigent

CVE-2026-62674

·

Published

2026-08-21

·

Updated

2026-09-10

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Omnigent versions prior to 0.3.0
Description An authenticated user with edit access to a session can replace a shared agent bundle because the system fails to reject bound shared or template agents where the agent.session id is None. By utilizing the 'PUT /sessions/{session id}/agent' endpoint, an attacker can add a stdio MCP server (Model Context Protocol, a standard for connecting AI models to external data sources and tools) to the shared agent. This allows the execution of attacker-controlled commands through the Omnigent runner process permissions, potentially exposing credentials, workspace data, internal services, and files.
Recommendations Update to version 0.3.0.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62674
GHSA-JRRM-9HC7-2V3H
PYSEC-2026-3874

Affected Products

Omnigent