omnigent
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting omnigentpage 1 of 1
- CVE-2026-62674CRITICALCVSS 9.0EG 9.0✓ Fixed in 0.3.02026-08-21
vulnerable: 0.0.1rc1 ... 0.3.0rc1 (12 versions)
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agen…
- CVE-2026-62675HIGHCVSS 8.8EG 8.8✓ Fixed in 0.3.02026-08-21
vulnerable: 0.0.1rc1 ... 0.3.0rc1 (12 versions)
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle d…
- CVE-2026-62676HIGHCVSS 7.1EG 7.1✓ Fixed in 0.3.02026-08-21
vulnerable: 0.0.1rc1 ... 0.3.0rc1 (12 versions)
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the time…
- CVE-2026-62677HIGHCVSS 8.8EG 8.8✓ Fixed in 0.3.02026-08-21
vulnerable: 0.0.1rc1 ... 0.3.0rc1 (12 versions)
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value becaus…
Check whether omnigent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for omnigent CVEs against the assets you own.
Start Free Scan →