All 4 CVE vulnerabilities found in omnigent, with AI-generated Chinese analysis, references, and POCs.
Vendor: omnigent-ai
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-62675 | Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools CWE-94 | 8.8 | High | 2026-08-21 |
| CVE-2026-62674 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE CWE-94 | 9.0 | Critical | 2026-08-21 |
| CVE-2026-62677 | Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE CWE-22 | 8.8 | High | 2026-08-21 |
| CVE-2026-62676 | Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py CWE-184 | 7.1 | High | 2026-08-21 |
All 4 known CVE vulnerabilities affecting omnigent with full Chinese analysis, references, and POCs where available.