omnigent vulnerabilities
CVEs whose affected-version data names the omnigent package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-62675High· 8.8Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle…
CVE-2026-62674Critical· 9.0Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template ag…
CVE-2026-62677High· 8.8Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value beca…
CVE-2026-62676High· 7.1Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the ti…