ouroboros-ai vulnerabilities
CVEs whose affected-version data names the ouroboros-ai package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-47211HighOuroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands …
▾ Twilightouroboros-ai · ouroboros-aiEPSS 0.17%via NVD
CVE-2026-66065Highouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
▾ Twilightouroboros-ai · ouroboros-aiEPSS 0.30%via OSV
GHSA-jv2h-4p9v-wf5wHighouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
▾ Twilightouroboros-ai · ouroboros-aivia GHSA