{"data":{"id":"f4fcf250-a83b-49f0-86a4-77a7504231b3","title":"CVE-2026-62674: Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /ses","summary":"Omnigent, an open-source framework for managing AI agents that write code, has a permission bypass vulnerability in versions before 0.3.0. An authenticated user with edit access to a session can replace a shared agent (an agent template used across multiple sessions) and inject a malicious command that executes with the same permissions as the Omnigent process, potentially exposing sensitive data like files, credentials, and internal services.","solution":"Update to version 0.3.0 or later, which fixes this vulnerability.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62674","publishedAt":"2026-08-21T18:16:49.460Z","cveId":"CVE-2026-62674","cweIds":["CWE-94"],"cvssScore":"9","cvssSeverity":"critical","severity":"critical","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["Omnigent"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-21T18:16:49.460Z","capecIds":["CAPEC-242"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}