CVE-2026-62676High· 7.1▾ TwilightOmnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the ti…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the timeout, nice, setsid, and stdbuf wrappers, command substitutions, and a single background control operator. A gated git push or gh write hidden with these forms produces no parsed operation, causing the github.py write_repos and write_branches allowlist and the working_dir.py workspace confinement policies to abstain and allow the command. An authenticated or prompt-injected agent can therefore push to an unauthorized repository or branch or escape the intended workspace. This issue is fixed in version 0.3.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
omnigent < 0.3.0Patched in:
omnigent 0.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-62675High· 8.8Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents
CVE-2026-62674Critical· 9.0Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents
CVE-2026-62677High· 8.8Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents
CVE-2026-55830High· 8.3RestrictedPython guard hooks can be shadowed via positional-only arguments
CVE-2026-67325High· 8.8GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature
CVE-2025-71351MediumPicklescan missing detection when calling built-in python library function timeit.timeit()