THREAT OPS › Threat News › [GHSA] GHSA-p8rw-8qj3-hf33 (high) — Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
[GHSA] GHSA-p8rw-8qj3-hf33 (high) — Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
GHSA-p8rw-8qj3-hf33 Severity: high CVE: CVE-2026-62677
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
### Summary
An authenticated, non-admin user can obtain **arbitrary host-filesystem read/write** (and host environment-secret disclosure) on an Omnigent **runner** by uploading an agent bundle whose `os_env.c
Indicators of compromise
- CVE-2026-62677cve
Original source: https://github.com/advisories/GHSA-p8rw-8qj3-hf33