Vulnerability in Omnigent AI Framework Allows Unauthorized Command Execution
CVE-2026-62674
What is CVE-2026-62674?
The Omnigent AI Framework, an open-source project for coding agents, exhibits a security flaw in its session management. Specifically, prior to version 0.3.0, it failed to appropriately enforce permissions when replacing shared or template agents. An authenticated user with editing capabilities could exploit this vulnerability to substitute a shared agent bundle and introduce a malicious stdio MCP server. Consequently, upon executing subsequent sessions utilizing that shared agent, commands could be executed with the privileges of the Omnigent runner process, leading to a potential compromise of sensitive data, including files, credentials, and access to internal services. Users are strongly urged to update to version 0.3.0 to mitigate this risk.
Affected Version(s)
omnigent < 0.3.0
