{"id":"CVE-2026-47211","aliases":["GHSA-c4m7-2gwp-vw76","PYSEC-2026-2857"],"url":"https://o3.security/vulnerability/CVE-2026-47211","summary":"Ouroboros: Remote Code Execution via Untrusted Project-Directory .env","details":"### Impact\nA Remote Code Execution (RCE) vulnerability was discovered in Ouroboros. If a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to arbitrary code execution and potential system takeover.\n\nThe vulnerability (CWE-426: Untrusted Search Path & CWE-15: External Control of System Setting) stems from Ouroboros loading the `.env` file from the current working directory. Prior to the patch, execution-affecting environment variables such as `OUROBOROS_CLI_PATH`, `OPENCODE_CLI_PATH`, and other backend selectors were accepted directly from this local `.env`. An attacker could include a malicious script in the repository and point the CLI path variable to it (e.g., `OUROBOROS_CLI_PATH=./malicious_script.sh`). When the user executes a command like `ouroboros init` or any command that instantiates the adapter, the malicious script is executed instead of the intended CLI.\n\n### Patches\nThe vulnerability has been patched in version 0.39.0 via PR #1078.\nThe fix establishes a strict trust boundary by applying a denylist to project-local `.env` loading. It blocks execution-affecting environment variables (such as runtime selectors and CLI path overrides) from being loaded from the project directory. Explicit constructor overrides and trusted user-owned home configurations (`~/.ouroboros/.env`) remain fully functional. \n\nUsers are strongly advised to upgrade to version 0.39.0 or later.\n\n### Workarounds\nIf upgrading is not immediately possible, users must carefully inspect any `.env` file inside cloned repositories before running Ouroboros commands to ensure it does not contain unexpected `OUROBOROS_*_CLI_PATH` or `OPENCODE_CLI_PATH` overrides.\n\n### References\n- GitHub PR: https://github.com/Q00/ouroboros/pull/1078","published":"2026-08-03T20:01:03.079Z","modified":"2026-09-12T03:30:39.196842255Z","cvss":null,"epss":{"score":0.00173,"percentile":0.07122,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ouroboros-ai","fixedVersion":"0.39.0"}],"fix":{"url":"https://github.com/Q00/ouroboros/commit/4e70b760b4eb157469b58645339ba831f6513d37","label":"Q00/ouroboros@4e70b76"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47211.json"},{"type":"ADVISORY","url":"https://github.com/Q00/ouroboros/security/advisories/GHSA-c4m7-2gwp-vw76"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47211"},{"type":"FIX","url":"https://github.com/Q00/ouroboros/commit/4e70b760b4eb157469b58645339ba831f6513d37"},{"type":"FIX","url":"https://github.com/Q00/ouroboros/pull/1078"},{"type":"PACKAGE","url":"https://github.com/Q00/ouroboros"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-12T03:30:39.196842255Z"}}