8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether omnigent is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.0
CVE-2026-62674
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
HIGH 8.8
CVE-2026-62675
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
HIGH 8.8
CVE-2026-62677
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
HIGH 7.1
CVE-2026-62676
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
CRITICAL 9.0
CVE-2026-62674
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
HIGH 8.8
CVE-2026-62677
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
HIGH 7.1
CVE-2026-62676
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
HIGH 8.8
CVE-2026-62675
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes