← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 21, 2026 · 18:16via CVEFeed

CVE-2026-62676 - Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

Brief

CVE ID : CVE-2026-62676

Published : Aug. 21, 2026, 6:16 p. m.

  • 53 minutes ago

Description : Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.

  • 0, the shared shell-command parser in omnigent/policies/builtins/_shell. py fails to recognize combined interpreter flags, the timeout, nice, setsid, and stdbuf wrappers, command substitutions, and a single background control operator.

A gated git push or gh write hidden with these forms produces no parsed operation, causing the github. py write_repos and write_branches allowlist and the working_dir. py workspace confinement policies to abstain and allow the command. An authenticated or prompt-injected agent can therefore push to an unauthorized repository or branch or escape the intended workspace. This issue is fixed in version 0.

  • 0.
Read more on CVEFeed