{"data":{"id":"25336153-1dea-48b0-8eac-8dff034db2b1","title":"CVE-2026-62677: Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authe","summary":"Omnigent, an open-source framework for running AI coding agents, had a vulnerability in versions before 0.3.0 where authenticated users could upload malicious agent bundles with specially crafted file paths that bypass security checks. This allowed attackers to access files and secrets outside the intended workspace using tools that read, write, and execute code. The vulnerability was fixed in version 0.3.0.","solution":"Update to version 0.3.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62677","publishedAt":"2026-08-21T18:16:49.887Z","cveId":"CVE-2026-62677","cweIds":["CWE-22"],"cvssScore":"8.8","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Omnigent"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-21T18:16:49.887Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}