{"id":"GHSA-jv2h-4p9v-wf5w","summary":"ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys","details":"### Impact\nThe CVE-2026-47211 fix (0.39.0) added `_UNTRUSTED_ENV_DENYLIST` to stop an untrusted project-directory `.env` from redirecting execution. The denylist was incomplete — several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a `.env` (auto-loaded at import, no review step):\n\n- **Backend config-home roots** `CODEX_HOME`, `OPENCODE_CONFIG`, `OPENCODE_CONFIG_DIR`, `XDG_CONFIG_HOME`: a spawned vendor CLI resolves its config from these. `CODEX_HOME=./.evil` + committed `./.evil/config.toml` redirects the nested Codex agent to attacker config — `mcp_servers.\u003cname\u003e.command/args` (RCE) and `approval_policy=\"never\"` / `sandbox_mode=\"danger-full-access\"` (silent removal of the human approval gate). (reported by matte1782)\n- **MCP bridge / plugin execution roster** `OUROBOROS_MCP_CONFIG` (the YAML's server `command`/`args` are spawned via stdio_client — RCE), `OUROBOROS_PLUGIN_LOCKFILE`, `OUROBOROS_PLUGIN_TRUST_ROOT` (redirect the installed-plugin roster / trust root so `ooo \u003cname\u003e` dispatches into attacker code). (reported by hackkim)\n- **SSRF guard toggle** `OUROBOROS_ALLOW_LOCAL_TRANSPORT` (re-enables loopback/private MCP transport targets).\n- **Instruction / capability roots** `OUROBOROS_AGENTS_DIR`, `COPILOT_CUSTOM_INSTRUCTIONS_DIRS` (replace spawned sub-agent role prompts), `OUROBOROS_RUNTIME_PROFILE` (backend selector), `OUROBOROS_TOOL_CAPABILITIES` (override YAML can lower a tool's `approval_class`, weakening the approval gate).\n\nAdditionally, the MCP bridge auto-loaded `./.ouroboros/mcp_servers.yaml` from the working directory (`create_bridge_from_env(cwd=Path.cwd())`), so running `ooo` inside a malicious repo spawned the committed roster's `command` — RCE with no `.env` at all. (cwd-branch noted by hackkim)\n\n### Patches\nFixed in 0.42.1. All listed keys were added to `_UNTRUSTED_ENV_DENYLIST`; the cwd auto-discovery branch was removed (only the explicit `OUROBOROS_MCP_CONFIG` env var and `~/.ouroboros/mcp_servers.yaml` remain, both trusted). The regression suite now derives from the source denylist to prevent future drift.\n\n### Workarounds\nDo not run Ouroboros from an untrusted/cloned repository directory; remove any project-directory `.env` and `./.ouroboros/mcp_servers.yaml` before running.\n\n### Credit\nReported privately via coordinated disclosure by matte1782 and hackkim (https://github.com/hackkim).","aliases":["CVE-2026-66065"],"modified":"2026-09-10T03:51:08.868868079Z","published":"2026-06-19T15:12:25Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-19T15:12:25Z","nvd_published_at":null,"cwe_ids":["CWE-15","CWE-94"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/Q00/ouroboros/security/advisories/GHSA-jv2h-4p9v-wf5w"},{"type":"PACKAGE","url":"https://github.com/Q00/ouroboros"}],"affected":[{"package":{"name":"ouroboros-ai","ecosystem":"PyPI","purl":"pkg:pypi/ouroboros-ai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.42.1"}]}],"versions":["0.1.0","0.1.0a1","0.1.1","0.10.0","0.11.0","0.11.1","0.12.0","0.12.1","0.12.2","0.13.0","0.13.1","0.13.2","0.13.3","0.13.4","0.13.5","0.13.6","0.13.7","0.14.0","0.14.1","0.15.0","0.16.0","0.17.0","0.18.0","0.18.1","0.19.0","0.19.1","0.2.0","0.2.1","0.2.2","0.2.3","0.20.0","0.21.0","0.21.1","0.22.0","0.23.0","0.23.1","0.23.2","0.24.0","0.25.0","0.25.1","0.25.2","0.26.0","0.26.0b1","0.26.0b2","0.26.0b3","0.26.0b4","0.26.0b5","0.26.0b7","0.26.1","0.26.2","0.26.3","0.26.4","0.26.5","0.26.6","0.27.0","0.27.1","0.27.2","0.28.0","0.28.1","0.28.2","0.28.3","0.28.4","0.28.5","0.28.6","0.28.7","0.28.8","0.29.0","0.29.1","0.29.2","0.3.0","0.30.0","0.31.0","0.31.1","0.32.0","0.33.0","0.34.0","0.35.0","0.36.0","0.36.1.dev20","0.36.1.dev21","0.36.1.dev22","0.36.1.dev23","0.36.1.dev24","0.36.1.dev25","0.36.1.dev26","0.36.1.dev27","0.36.1.dev28","0.36.1.dev29","0.36.1.dev30","0.36.1.dev31","0.36.1.dev32","0.36.1.dev33","0.36.1.dev34","0.36.1.dev36","0.36.1.dev41","0.36.1.dev49","0.36.1.dev50","0.36.1.dev51","0.36.1.dev52","0.36.1.dev53","0.36.1.dev54","0.36.1.dev55","0.36.1.dev56","0.36.1.dev57","0.36.1.dev58","0.36.1.dev59","0.36.1.dev60","0.36.1.dev61","0.36.1.dev62","0.36.1.dev63","0.36.1.dev64","0.36.1.dev65","0.36.1.dev66","0.36.1.dev67","0.36.1.dev68","0.36.1.dev69","0.36.1.dev70","0.36.1.dev71","0.37.0","0.37.1.dev1","0.37.1.dev10","0.37.1.dev11","0.37.1.dev12","0.37.1.dev13","0.37.1.dev14","0.37.1.dev15","0.37.1.dev16","0.37.1.dev17","0.37.1.dev18","0.37.1.dev19","0.37.1.dev2","0.37.1.dev20","0.37.1.dev21","0.37.1.dev22","0.37.1.dev23","0.37.1.dev24","0.37.1.dev25","0.37.1.dev26","0.37.1.dev27","0.37.1.dev28","0.37.1.dev29","0.37.1.dev3","0.37.1.dev30","0.37.1.dev31","0.37.1.dev32","0.37.1.dev33","0.37.1.dev34","0.37.1.dev35","0.37.1.dev36","0.37.1.dev37","0.37.1.dev38","0.37.1.dev39","0.37.1.dev4","0.37.1.dev40","0.37.1.dev5","0.37.1.dev50","0.37.1.dev51","0.37.1.dev6","0.37.1.dev7","0.37.1.dev8","0.37.1.dev9","0.38.0","0.38.1","0.38.1.dev1","0.38.1.dev2","0.38.1.dev3","0.38.1.dev4","0.38.2","0.38.2.dev3","0.38.3.dev1","0.38.3.dev10","0.38.3.dev100","0.38.3.dev101","0.38.3.dev102","0.38.3.dev103","0.38.3.dev104","0.38.3.dev105","0.38.3.dev106","0.38.3.dev107","0.38.3.dev108","0.38.3.dev109","0.38.3.dev11","0.38.3.dev110","0.38.3.dev111","0.38.3.dev112","0.38.3.dev113","0.38.3.dev114","0.38.3.dev115","0.38.3.dev116","0.38.3.dev117","0.38.3.dev118","0.38.3.dev119","0.38.3.dev12","0.38.3.dev120","0.38.3.dev121","0.38.3.dev122","0.38.3.dev123","0.38.3.dev124","0.38.3.dev125","0.38.3.dev126","0.38.3.dev127","0.38.3.dev128","0.38.3.dev129","0.38.3.dev13","0.38.3.dev130","0.38.3.dev131","0.38.3.dev132","0.38.3.dev133","0.38.3.dev134","0.38.3.dev135","0.38.3.dev136","0.38.3.dev137","0.38.3.dev138","0.38.3.dev139","0.38.3.dev14","0.38.3.dev140","0.38.3.dev141","0.38.3.dev142","0.38.3.dev143","0.38.3.dev144","0.38.3.dev145","0.38.3.dev146","0.38.3.dev147","0.38.3.dev148","0.38.3.dev149","0.38.3.dev15","0.38.3.dev150","0.38.3.dev151","0.38.3.dev152","0.38.3.dev153","0.38.3.dev154","0.38.3.dev155","0.38.3.dev156","0.38.3.dev157","0.38.3.dev158","0.38.3.dev159","0.38.3.dev16","0.38.3.dev160","0.38.3.dev161","0.38.3.dev162","0.38.3.dev163","0.38.3.dev164","0.38.3.dev165","0.38.3.dev166","0.38.3.dev17","0.38.3.dev18","0.38.3.dev19","0.38.3.dev2","0.38.3.dev20","0.38.3.dev21","0.38.3.dev22","0.38.3.dev23","0.38.3.dev24","0.38.3.dev25","0.38.3.dev26","0.38.3.dev27","0.38.3.dev28","0.38.3.dev29","0.38.3.dev3","0.38.3.dev30","0.38.3.dev31","0.38.3.dev33","0.38.3.dev4","0.38.3.dev41","0.38.3.dev43","0.38.3.dev44","0.38.3.dev45","0.38.3.dev46","0.38.3.dev47","0.38.3.dev48","0.38.3.dev49","0.38.3.dev5","0.38.3.dev50","0.38.3.dev51","0.38.3.dev52","0.38.3.dev53","0.38.3.dev54","0.38.3.dev55","0.38.3.dev56","0.38.3.dev57","0.38.3.dev6","0.38.3.dev60","0.38.3.dev66","0.38.3.dev7","0.38.3.dev76","0.38.3.dev8","0.38.3.dev86","0.38.3.dev89","0.38.3.dev9","0.38.3.dev91","0.38.3.dev93","0.38.3.dev94","0.38.3.dev98","0.38.3.dev99","0.39.0","0.39.1","0.39.1.dev1","0.39.1.dev10","0.39.1.dev11","0.39.1.dev12","0.39.1.dev13","0.39.1.dev14","0.39.1.dev15","0.39.1.dev16","0.39.1.dev17","0.39.1.dev18","0.39.1.dev19","0.39.1.dev2","0.39.1.dev20","0.39.1.dev21","0.39.1.dev22","0.39.1.dev23","0.39.1.dev24","0.39.1.dev25","0.39.1.dev26","0.39.1.dev27","0.39.1.dev28","0.39.1.dev29","0.39.1.dev3","0.39.1.dev30","0.39.1.dev31","0.39.1.dev32","0.39.1.dev33","0.39.1.dev4","0.39.1.dev5","0.39.1.dev6","0.39.1.dev7","0.39.1.dev8","0.39.1.dev9","0.39.2.dev1","0.39.2.dev10","0.39.2.dev100","0.39.2.dev101","0.39.2.dev102","0.39.2.dev103","0.39.2.dev104","0.39.2.dev105","0.39.2.dev106","0.39.2.dev107","0.39.2.dev108","0.39.2.dev109","0.39.2.dev11","0.39.2.dev110","0.39.2.dev111","0.39.2.dev12","0.39.2.dev13","0.39.2.dev14","0.39.2.dev15","0.39.2.dev16","0.39.2.dev17","0.39.2.dev18","0.39.2.dev19","0.39.2.dev2","0.39.2.dev20","0.39.2.dev21","0.39.2.dev22","0.39.2.dev23","0.39.2.dev24","0.39.2.dev25","0.39.2.dev26","0.39.2.dev27","0.39.2.dev28","0.39.2.dev29","0.39.2.dev3","0.39.2.dev30","0.39.2.dev31","0.39.2.dev32","0.39.2.dev33","0.39.2.dev34","0.39.2.dev35","0.39.2.dev36","0.39.2.dev37","0.39.2.dev38","0.39.2.dev39","0.39.2.dev4","0.39.2.dev40","0.39.2.dev41","0.39.2.dev42","0.39.2.dev43","0.39.2.dev44","0.39.2.dev45","0.39.2.dev46","0.39.2.dev47","0.39.2.dev48","0.39.2.dev49","0.39.2.dev5","0.39.2.dev50","0.39.2.dev51","0.39.2.dev52","0.39.2.dev53","0.39.2.dev54","0.39.2.dev55","0.39.2.dev56","0.39.2.dev57","0.39.2.dev58","0.39.2.dev59","0.39.2.dev6","0.39.2.dev60","0.39.2.dev61","0.39.2.dev62","0.39.2.dev63","0.39.2.dev64","0.39.2.dev65","0.39.2.dev66","0.39.2.dev67","0.39.2.dev68","0.39.2.dev69","0.39.2.dev7","0.39.2.dev70","0.39.2.dev71","0.39.2.dev72","0.39.2.dev73","0.39.2.dev74","0.39.2.dev75","0.39.2.dev76","0.39.2.dev77","0.39.2.dev78","0.39.2.dev79","0.39.2.dev8","0.39.2.dev80","0.39.2.dev81","0.39.2.dev82","0.39.2.dev83","0.39.2.dev84","0.39.2.dev85","0.39.2.dev86","0.39.2.dev87","0.39.2.dev88","0.39.2.dev89","0.39.2.dev9","0.39.2.dev90","0.39.2.dev91","0.39.2.dev92","0.39.2.dev93","0.39.2.dev94","0.39.2.dev95","0.39.2.dev96","0.39.2.dev97","0.39.2.dev98","0.39.2.dev99","0.4.0","0.4.1","0.40.0","0.40.1","0.40.1.dev1","0.40.1.dev2","0.40.2.dev1","0.40.2.dev10","0.40.2.dev11","0.40.2.dev12","0.40.2.dev13","0.40.2.dev14","0.40.2.dev15","0.40.2.dev16","0.40.2.dev17","0.40.2.dev18","0.40.2.dev19","0.40.2.dev2","0.40.2.dev20","0.40.2.dev21","0.40.2.dev22","0.40.2.dev23","0.40.2.dev3","0.40.2.dev4","0.40.2.dev5","0.40.2.dev6","0.40.2.dev7","0.40.2.dev8","0.40.2.dev9","0.41.0","0.41.1.dev1","0.41.1.dev10","0.41.1.dev11","0.41.1.dev12","0.41.1.dev13","0.41.1.dev14","0.41.1.dev15","0.41.1.dev16","0.41.1.dev17","0.41.1.dev18","0.41.1.dev19","0.41.1.dev2","0.41.1.dev20","0.41.1.dev21","0.41.1.dev22","0.41.1.dev23","0.41.1.dev24","0.41.1.dev25","0.41.1.dev26","0.41.1.dev27","0.41.1.dev28","0.41.1.dev29","0.41.1.dev3","0.41.1.dev30","0.41.1.dev31","0.41.1.dev32","0.41.1.dev33","0.41.1.dev34","0.41.1.dev35","0.41.1.dev36","0.41.1.dev37","0.41.1.dev38","0.41.1.dev39","0.41.1.dev4","0.41.1.dev40","0.41.1.dev41","0.41.1.dev42","0.41.1.dev43","0.41.1.dev44","0.41.1.dev45","0.41.1.dev46","0.41.1.dev47","0.41.1.dev48","0.41.1.dev49","0.41.1.dev5","0.41.1.dev50","0.41.1.dev51","0.41.1.dev52","0.41.1.dev53","0.41.1.dev54","0.41.1.dev55","0.41.1.dev56","0.41.1.dev57","0.41.1.dev58","0.41.1.dev6","0.41.1.dev7","0.41.1.dev8","0.41.1.dev9","0.42.0","0.42.1.dev1","0.42.1.dev2","0.5.0","0.5.1","0.6.0","0.7.0","0.8.0","0.9.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.42.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jv2h-4p9v-wf5w/GHSA-jv2h-4p9v-wf5w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}