CVE-2026-62675
8.8omnigent-ai · omnigent
A code injection vulnerability in the Omnigent AI agent framework allows authenticated users to execute arbitrary code via improper generation control.
Executive summary
An authenticated code injection vulnerability in Omnigent before version 0.3.0 poses a critical risk to system integrity and remote command execution.
Vulnerability
This vulnerability is caused by improper control of code generation (CWE-94). An authenticated attacker can leverage this flaw to inject malicious code into the framework, which is then executed with the privileges of the application.
Business impact
The ability to execute arbitrary code on a system hosting AI agents can lead to complete system compromise, data exfiltration, or the deployment of persistent backdoors. With a CVSS score of 8.8, this high-severity vulnerability represents a significant threat to internal infrastructure and sensitive data assets.
Remediation
Immediate Action: Update the Omnigent framework to version 0.3.0 or later as provided in the official GitHub repository.
Proactive Monitoring: Review audit logs for unusual agent behavior, unexpected code generation requests, or unauthorized modifications to source files managed by the framework.
Compensating Controls: Implement strict network segmentation for systems running AI orchestration harnesses to limit the potential reach of a compromised agent.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution, organizations utilizing Omnigent must prioritize the update to version 0.3.0 immediately. Failure to patch this vulnerability leaves the underlying host environment exposed to significant exploitation risks.