AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T18:16:49.887Z and has not been modified since then. The Omnigent open-source AI agent framework has a vulnerability that allows an authenticated user to upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value. This could potentially allow access to sensitive [truncated]
CVE-2026-62676 debrief: Omnigent AI agent framework vulnerability allows unauthorized repository or branch pushes and workspace escape. The shared shell-command parser in Omnigent versions prior to 0.3.0 fails to recognize certain flags, wrappers, command substitutions, and control operators. This oversight enables authenticated or prompt-injected agents to push to unauthorized repositories or branches or [truncated]
CVE-2026-62675 is a high-severity vulnerability in the Omnigent open-source AI agent framework. Prior to version 0.3.0, the framework allows an authenticated user to execute a local command with runner process permissions by providing a malicious agent bundle. This issue can expose sensitive information and impact availability. The vulnerability is caused by the validate_agent_bundle function in omnigent/ [truncated]
CVE-2026-62674 is a critical vulnerability in the Omnigent open-source AI agent framework. An authenticated user with edit access to a session can replace a shared agent bundle, leading to potential command execution with the Omnigent runner process permissions. This can result in exposure of files, credentials, workspace data, internal services, and runner availability. Omnigent users and administrators [truncated]