{"data":{"id":"a8baf45b-250d-49ad-b027-f069c8c235b1","title":"CVE-2026-62676: Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shar","summary":"Omnigent is an open-source framework for running AI agents that write code. Before version 0.3.0, its command parser had a bug that failed to recognize certain shell command patterns (like combined flags, command substitutions, and background operators), which allowed security policies meant to restrict where agents could push code or work to be bypassed. An attacker using a compromised or manipulated AI agent could push code to unauthorized repositories or escape the intended workspace boundaries.","solution":"Update to version 0.3.0 or later, which fixes the issue.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62676","publishedAt":"2026-08-21T18:16:49.743Z","cveId":"CVE-2026-62676","cweIds":["CWE-184"],"cvssScore":"7.1","cvssSeverity":"high","severity":"high","attackType":["prompt_injection","supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["Omnigent"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-21T18:16:49.743Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010","AML.T0051"]}}