Local-First Runtime Vulnerability in Ouroboros by Q00
CVE-2026-66065
8.4HIGH
What is CVE-2026-66065?
The Ouroboros local-first runtime for AI coding agents has a vulnerability related to an incomplete denylist that could enable arbitrary command execution. Versions before 0.42.1 fail to block several execution-routing keys of the remote code execution class, which can be exploited via malicious repositories containing .env files. These files are auto-loaded during import without any review process, allowing attackers to manipulate the behavior of agents and configurations. Although a fix was introduced in version 0.42.1, it did not cover all security loopholes, leaving pathways for manipulation of backend configurations and re-enabling of locally blocked transports, thus undermining the system's overall security.
Affected Version(s)
ouroboros < 0.42.1
