{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/omnigent/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:omnigent:omnigent:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9,"id":"CVE-2026-62674"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Omnigent (\u003c 0.3.0)"],"_cs_severities":["high"],"_cs_tags":["rce","vulnerability","webserver"],"_cs_type":"advisory","_cs_vendors":["Omnigent"],"content_html":"\u003cp\u003eOmnigent versions prior to 0.3.0 are vulnerable to an authenticated Remote Code Execution (RCE) flaw due to insufficient validation of shared/template agents. The endpoint \u003ccode\u003ePUT /sessions/{session_id}/agent\u003c/code\u003e allows authenticated users to upload full agent bundles. While the application UI and secondary endpoints correctly identify shared/template agents (where \u003ccode\u003eagent.session_id\u003c/code\u003e is \u003ccode\u003eNone\u003c/code\u003e) as read-only and block modification, the primary bundle upload route fails to enforce this check.\u003c/p\u003e\n\u003cp\u003eBy submitting a crafted bundle to this endpoint, an attacker can overwrite the global configuration of a shared agent. If the uploaded bundle includes a \u003ccode\u003estdio\u003c/code\u003e MCP server configuration, the Omnigent runner process will execute the defined command as a subprocess whenever that shared agent is invoked by any user session. This effectively weaponizes shared infrastructure to execute arbitrary code with the runner's system permissions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Omnigent platform with valid user credentials.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an update request to the \u003ccode\u003ePUT /sessions/{session_id}/agent\u003c/code\u003e endpoint for their current session.\u003c/li\u003e\n\u003cli\u003eAttacker submits a maliciously crafted agent bundle containing a \u003ccode\u003estdio\u003c/code\u003e MCP server configuration that references an attacker-supplied command.\u003c/li\u003e\n\u003cli\u003eThe backend API fails to validate if the bound agent is a read-only shared/template agent.\u003c/li\u003e\n\u003cli\u003eThe server overwrites the global agent configuration in the data store with the malicious bundle.\u003c/li\u003e\n\u003cli\u003eA victim or administrator initiates a new session using the poisoned shared/template agent.\u003c/li\u003e\n\u003cli\u003eThe Omnigent runner environment processes the agent bundle and attempts to initialize the \u003ccode\u003estdio\u003c/code\u003e MCP server.\u003c/li\u003e\n\u003cli\u003eThe runner process spawns the attacker-specified command as a subprocess, resulting in remote code execution on the runner host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to execute arbitrary code on Omnigent runner hosts with the permissions of the runner process. This enables unauthorized file access, credential theft, modification of workspace data, and potential lateral movement into internal services reachable by the runner. Because shared agents are often used by multiple users, a single successful poisoning can compromise sessions across an entire organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpgrade all instances of Omnigent to version 0.3.0 or later immediately to patch the validation logic in the agent bundle upload process. As a temporary compensatory control, monitor server logs for high-frequency or unauthorized access to the \u003ccode\u003ePUT /sessions/{session_id}/agent\u003c/code\u003e endpoint by non-administrative users.\u003c/p\u003e\n","date_modified":"2026-09-03T00:04:22Z","date_published":"2026-09-03T00:02:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-omnigent-rce/","summary":"An improper access control vulnerability in Omnigent allows authenticated users to overwrite shared agent bundles, enabling arbitrary command execution on runner infrastructure via malicious MCP server configuration.","title":"Omnigent Shared Agent Bundle Overwrite Leads to Runner RCE","url":"https://feed.craftedsignal.io/briefs/2026-09-omnigent-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Omnigent","version":"https://jsonfeed.org/version/1.1"}