CVE-2026-62675: Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipar
Summary
Omnigent is an open-source framework for managing AI agents that write code. Before version 0.3.0, it had a security flaw where authenticated users could upload agent bundles (packages of code and configuration) that contained malicious Python commands, which the system would then execute with full permissions of the process running Omnigent, potentially exposing sensitive files, passwords, and internal data.
Solution / Mitigation
This issue is fixed in version 0.3.0.
Vulnerability Details
8.8(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
network
low
low
none
August 21, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-62675
First tracked: August 21, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 92%