Path Traversal Vulnerability in Omnigent AI Framework
CVE-2026-62677
8.8HIGH
What is CVE-2026-62677?
In the Omnigent AI framework, an authenticated user can upload a session-scoped agent bundle containing an absolute or traversal path in the os_env.cwd value. This flaw arises because the system stores this value verbatim without adequate constraints. On environments where OMNIGENT_RUNNER_WORKSPACE is not configured, it allows the preserved path to be treated as a trusted root, leading to unauthorized access to files and environmental secrets outside the designated workspace. This vulnerability has been addressed in version 0.3.0.
Affected Version(s)
omnigent < 0.3.0
