Omnigent: Multiple Authenticated RCE and Policy Bypass Vulnerabilities
Four critical vulnerabilities in Omnigent allow authenticated users to execute arbitrary code on runner hosts through malicious agent bundle uploads, unvalidated working directories, and guardrail policy bypasses. These affect shared agent overwrites, Python callable tools, filesystem access controls, and shell command policy evaluation.
Disclosed 2 September 2026 · Record updated 13 September 2026
Impact
Authenticated users can achieve remote code execution on Omnigent runner hosts, bypass security policies, overwrite shared agents, access arbitrary host filesystems, and exfiltrate secrets through multiple independent vulnerabilities in bundle validation and policy enforcement.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-756x-9hf6-q4h4
- github.comhttps://github.com/advisories/GHSA-jrrm-9hc7-2v3h
- github.comhttps://github.com/advisories/GHSA-p8rw-8qj3-hf33
- github.comhttps://github.com/advisories/GHSA-7mqg-cx4g-x2rf
