THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p8rw-8qj3-hf33 (high) — Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

[GHSA] GHSA-p8rw-8qj3-hf33 (high) — Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

medgithub_advisoriesPublished 2026-09-02

GHSA-p8rw-8qj3-hf33 Severity: high CVE: CVE-2026-62677

Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

### Summary

An authenticated, non-admin user can obtain **arbitrary host-filesystem read/write** (and host environment-secret disclosure) on an Omnigent **runner** by uploading an agent bundle whose `os_env.c

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p8rw-8qj3-hf33