Evidence record / omnigent
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.
2026-09-21-omnigent-three-bundle-upload-advisories-published-2026-09-16-all-fixed-in-v0-14-0-by-one
Three bundle-upload advisories published 2026-09-16, all fixed in v0.14.0 by one PR. What each actually allows, all requiring an authenticated user who can upload an agent bundle to a multi-user server:
- GHSA-q5jc: the policy-handler allowlist, the defense the June advisory family relied on, was skipped for the single-file omnigent YAML shape and never read the
function:key. A policy withfunction: {path: <module.attr>}was imported and called at session start before thecallable()check: arbitrary Python import-and-call on the runner/server. The policy system itself was the RCE vector. - GHSA-598r: a terminal’s
os_env.cwdwas not validated on upload and wins over the runner workspace at runtime, so withsandbox.type: noneit yields an unconfined host shell outside the workspace.OMNIGENT_RUNNER_WORKSPACEdoes not mitigate it. - GHSA-p5x3: the same cwd check did not recurse into sub-agents; mitigated by
OMNIGENT_RUNNER_WORKSPACE. The advisories state the fix enforces the upload boundary only; it does not change terminal runtime cwd precedence, and trusted local configurations are out of scope.
Channel: tagged-release. Half: defect (closed). Date: advisories published 2026-09-16; fix released 2026-09-15.
Operator consequence: Upgrade any server that accepts bundles from more than one user to v0.14.0. Before upgrading, re-audit uploaded bundles for function: policies with no handler/callable, absolute or .. cwd on terminals and sub-agents. Do not treat a registered-handler allowlist as containment on <=0.13.0. Single-user local installs are outside the stated threat model.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-omnigent-three-bundle-upload-advisories-published-2026-09-16-all-fixed-in-v0-14-0-by-one
Accepted signals
Profile citations
- omnigent / claim / bundle-advisories
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact