Ouroboros AI coding agent local code execution via .env loading
Ouroboros versions prior to 0.39.0 allow arbitrary code execution when users run commands in directories containing malicious repositories, as the runtime loads and executes environment variables from .env files without validation. A second vulnerability in versions prior to 0.42.1 bypasses the initial fix through an incomplete denylist of environment variables.
Disclosed 3 August 2026 · Record updated 13 September 2026
Impact
Arbitrary code execution and potential system takeover when running Ouroboros in directories with malicious repositories containing .env files that redirect CLI execution paths or bypass approval gates.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-47211
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-66065
