THREAT OPS › Threat News › [GHSA] GHSA-756x-9hf6-q4h4 (high) — Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
[GHSA] GHSA-756x-9hf6-q4h4 (high) — Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
GHSA-756x-9hf6-q4h4 Severity: high CVE: CVE-2026-62675
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
### Summary
An authenticated user can upload a crafted agent bundle that defines a server-side Python callable tool. The server validates the uploaded bundle, but it does not block dangerous `callable:` paths in untrusted user-provided agent configs.
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 23d42d9a7d46a3b6a0b40d5bf4125b91193bf831sha1
- CVE-2026-62675cve
Original source: https://github.com/advisories/GHSA-756x-9hf6-q4h4