THREAT OPS › Threat News › [GHSA] GHSA-hf57-cqmx-p4gr (critical) — OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
[GHSA] GHSA-hf57-cqmx-p4gr (critical) — OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
GHSA-hf57-cqmx-p4gr Severity: critical CVE: CVE-2026-88062
OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
## 2. Summary
`POST /api/acp/agents` registers a custom ACP agent. The endpoint accepts user-controlled `binary` and `versionCommand` values. After saving the custom agent, the same request calls `refreshAgentCache()`, which triggers agent version detection. The version probe event
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-88062cve
Original source: https://github.com/advisories/GHSA-hf57-cqmx-p4gr