VYPR

PyPI package

omnigent

pkg:pypi/omnigent

Vulnerabilities (4)

  • CVE-2026-62677HigAug 21, 2026
    affected < 0.3.0fixed 0.3.0

    Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value because omnigent/spec/parser.py stores the valu

  • CVE-2026-62676HigAug 21, 2026
    affected < 0.3.0fixed 0.3.0

    Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the timeout, nice, setsid, and stdbuf wrappers, c

  • CVE-2026-62675HigAug 21, 2026
    affected < 0.3.0fixed 0.3.0

    Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not reject a tools..callable dotted P

  • CVE-2026-62674CriAug 21, 2026
    affected < 0.3.0fixed 0.3.0

    Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose agent.session_id is None. An auth