AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T18:16:49.887Z and has not been modified since then. The Omnigent open-source AI agent framework has a vulnerability that allows an authenticated user to upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value. This could potentially allow access to sensitive [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T18:16:49.743Z and has not been modified since then. CVE-2026-62676 is a vulnerability in Omnigent, an open-source AI agent framework and meta-harness for orchestrating coding agents. The shared shell-command parser in Omnigent versions prior to 0.3.0 fails to recognize combined interpreter flags, [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T18:16:49.603Z and has not been modified since then. This HIGH severity vulnerability in Omnigent AI agent framework versions prior to 0.3.0 allows an authenticated user to execute local commands with runner process permissions by crafting a malicious agent bundle. The issue arises from inadequate [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T18:16:49.460Z and has not been modified since then. This critical vulnerability exists in Omnigent versions prior to 0.3.0, where an authenticated user with edit access to a session can replace a shared agent bundle, potentially leading to command execution with Omnigent runner process permission [truncated]