PT-2026-79413 · Omnigent · Omnigent

CVE-2026-62676

·

Published

2026-08-21

·

Updated

2026-09-10

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Omnigent versions prior to 0.3.0
Description The shared shell-command parser in omnigent/policies/builtins/ shell.py fails to recognize combined interpreter flags, command substitutions, a single background control operator, and wrappers such as timeout, nice, setsid, and stdbuf. This failure allows a gated git push or gh write command to bypass the write repos and write branches allowlists in github.py and the workspace confinement policies in working dir.py. Consequently, an authenticated or prompt-injected agent can push to an unauthorized repository or branch or escape the intended workspace.
Recommendations Update to version 0.3.0.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62676
GHSA-7MQG-CX4G-X2RF
PYSEC-2026-3873

Affected Products

Omnigent