THREAT OPS › Threat News › [GHSA] GHSA-jrrm-9hc7-2v3h (critical) — Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
[GHSA] GHSA-jrrm-9hc7-2v3h (critical) — Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
GHSA-jrrm-9hc7-2v3h Severity: critical CVE: CVE-2026-62674
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
### Summary
An authenticated user with edit access to their own session can overwrite a shared/template agent by uploading a full agent bundle through `PUT /sessions/{session_id}/agent`.
Shared/template agents are shown as not MCP-editable, but this upload path s
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 10f5ae3110e162f96fb99bb6662c581abdc56cd6sha1
- CVE-2026-62674cve
Original source: https://github.com/advisories/GHSA-jrrm-9hc7-2v3h