THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-756x-9hf6-q4h4 (high) — Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

[GHSA] GHSA-756x-9hf6-q4h4 (high) — Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

highgithub_advisoriesPublished 2026-09-02

GHSA-756x-9hf6-q4h4 Severity: high CVE: CVE-2026-62675

Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

### Summary

An authenticated user can upload a crafted agent bundle that defines a server-side Python callable tool. The server validates the uploaded bundle, but it does not block dangerous `callable:` paths in untrusted user-provided agent configs.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-756x-9hf6-q4h4