{"id":"PYSEC-2026-2857","summary":"ouroboros-ai Vulnerable to Remote Code Execution via Untrusted Project-Directory .env","details":"### Impact\nA Remote Code Execution (RCE) vulnerability was discovered in Ouroboros. If a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to arbitrary code execution and potential system takeover.\n\nThe vulnerability (CWE-426: Untrusted Search Path & CWE-15: External Control of System Setting) stems from Ouroboros loading the `.env` file from the current working directory. Prior to the patch, execution-affecting environment variables such as `OUROBOROS_CLI_PATH`, `OPENCODE_CLI_PATH`, and other backend selectors were accepted directly from this local `.env`. An attacker could include a malicious script in the repository and point the CLI path variable to it (e.g., `OUROBOROS_CLI_PATH=./malicious_script.sh`). When the user executes a command like `ouroboros init` or any command that instantiates the adapter, the malicious script is executed instead of the intended CLI.\n\n### Patches\nThe vulnerability has been patched in version 0.39.0 via PR #1078.\nThe fix establishes a strict trust boundary by applying a denylist to project-local `.env` loading. It blocks execution-affecting environment variables (such as runtime selectors and CLI path overrides) from being loaded from the project directory. Explicit constructor overrides and trusted user-owned home configurations (`~/.ouroboros/.env`) remain fully functional. \n\nUsers are strongly advised to upgrade to version 0.39.0 or later.\n\n### Workarounds\nIf upgrading is not immediately possible, users must carefully inspect any `.env` file inside cloned repositories before running Ouroboros commands to ensure it does not contain unexpected `OUROBOROS_*_CLI_PATH` or `OPENCODE_CLI_PATH` overrides.\n\n### References\n- GitHub PR: https://github.com/Q00/ouroboros/pull/1078","aliases":["CVE-2026-47211","GHSA-c4m7-2gwp-vw76"],"modified":"2026-07-13T16:32:34.219872134Z","published":"2026-07-13T15:19:15.482658Z","references":[{"type":"WEB","url":"https://github.com/Q00/ouroboros/security/advisories/GHSA-c4m7-2gwp-vw76"},{"type":"WEB","url":"https://github.com/Q00/ouroboros/pull/1078"},{"type":"WEB","url":"https://github.com/Q00/ouroboros/commit/4e70b760b4eb157469b58645339ba831f6513d37"},{"type":"PACKAGE","url":"https://github.com/Q00/ouroboros"},{"type":"PACKAGE","url":"https://pypi.org/project/ouroboros-ai"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-c4m7-2gwp-vw76"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47211"}],"affected":[{"package":{"name":"ouroboros-ai","ecosystem":"PyPI","purl":"pkg:pypi/ouroboros-ai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.39.0"}]}],"versions":["0.1.0","0.1.0a1","0.1.1","0.10.0","0.11.0","0.11.1","0.12.0","0.12.1","0.12.2","0.13.0","0.13.1","0.13.2","0.13.3","0.13.4","0.13.5","0.13.6","0.13.7","0.14.0","0.14.1","0.15.0","0.16.0","0.17.0","0.18.0","0.18.1","0.19.0","0.19.1","0.2.0","0.2.1","0.2.2","0.2.3","0.20.0","0.21.0","0.21.1","0.22.0","0.23.0","0.23.1","0.23.2","0.24.0","0.25.0","0.25.1","0.25.2","0.26.0","0.26.0b1","0.26.0b2","0.26.0b3","0.26.0b4","0.26.0b5","0.26.0b7","0.26.1","0.26.2","0.26.3","0.26.4","0.26.5","0.26.6","0.27.0","0.27.1","0.27.2","0.28.0","0.28.1","0.28.2","0.28.3","0.28.4","0.28.5","0.28.6","0.28.7","0.28.8","0.29.0","0.29.1","0.29.2","0.3.0","0.30.0","0.31.0","0.31.1","0.32.0","0.33.0","0.34.0","0.35.0","0.36.0","0.36.1.dev20","0.36.1.dev21","0.36.1.dev22","0.36.1.dev23","0.36.1.dev24","0.36.1.dev25","0.36.1.dev26","0.36.1.dev27","0.36.1.dev28","0.36.1.dev29","0.36.1.dev30","0.36.1.dev31","0.36.1.dev32","0.36.1.dev33","0.36.1.dev34","0.36.1.dev36","0.36.1.dev41","0.36.1.dev49","0.36.1.dev50","0.36.1.dev51","0.36.1.dev52","0.36.1.dev53","0.36.1.dev54","0.36.1.dev55","0.36.1.dev56","0.36.1.dev57","0.36.1.dev58","0.36.1.dev59","0.36.1.dev60","0.36.1.dev61","0.36.1.dev62","0.36.1.dev63","0.36.1.dev64","0.36.1.dev65","0.36.1.dev66","0.36.1.dev67","0.36.1.dev68","0.36.1.dev69","0.36.1.dev70","0.36.1.dev71","0.37.0","0.37.1.dev1","0.37.1.dev10","0.37.1.dev11","0.37.1.dev12","0.37.1.dev13","0.37.1.dev14","0.37.1.dev15","0.37.1.dev16","0.37.1.dev17","0.37.1.dev18","0.37.1.dev19","0.37.1.dev2","0.37.1.dev20","0.37.1.dev21","0.37.1.dev22","0.37.1.dev23","0.37.1.dev24","0.37.1.dev25","0.37.1.dev26","0.37.1.dev27","0.37.1.dev28","0.37.1.dev29","0.37.1.dev3","0.37.1.dev30","0.37.1.dev31","0.37.1.dev32","0.37.1.dev33","0.37.1.dev34","0.37.1.dev35","0.37.1.dev36","0.37.1.dev37","0.37.1.dev38","0.37.1.dev39","0.37.1.dev4","0.37.1.dev40","0.37.1.dev5","0.37.1.dev50","0.37.1.dev51","0.37.1.dev6","0.37.1.dev7","0.37.1.dev8","0.37.1.dev9","0.38.0","0.38.1","0.38.1.dev1","0.38.1.dev2","0.38.1.dev3","0.38.1.dev4","0.38.2","0.38.2.dev3","0.38.3.dev1","0.38.3.dev10","0.38.3.dev100","0.38.3.dev101","0.38.3.dev102","0.38.3.dev103","0.38.3.dev104","0.38.3.dev105","0.38.3.dev106","0.38.3.dev107","0.38.3.dev108","0.38.3.dev109","0.38.3.dev11","0.38.3.dev110","0.38.3.dev111","0.38.3.dev112","0.38.3.dev113","0.38.3.dev114","0.38.3.dev115","0.38.3.dev116","0.38.3.dev117","0.38.3.dev118","0.38.3.dev119","0.38.3.dev12","0.38.3.dev120","0.38.3.dev121","0.38.3.dev122","0.38.3.dev123","0.38.3.dev124","0.38.3.dev125","0.38.3.dev126","0.38.3.dev127","0.38.3.dev128","0.38.3.dev129","0.38.3.dev13","0.38.3.dev130","0.38.3.dev131","0.38.3.dev132","0.38.3.dev133","0.38.3.dev134","0.38.3.dev135","0.38.3.dev136","0.38.3.dev137","0.38.3.dev138","0.38.3.dev139","0.38.3.dev14","0.38.3.dev140","0.38.3.dev141","0.38.3.dev142","0.38.3.dev143","0.38.3.dev144","0.38.3.dev145","0.38.3.dev146","0.38.3.dev147","0.38.3.dev148","0.38.3.dev149","0.38.3.dev15","0.38.3.dev150","0.38.3.dev151","0.38.3.dev152","0.38.3.dev153","0.38.3.dev154","0.38.3.dev155","0.38.3.dev156","0.38.3.dev157","0.38.3.dev158","0.38.3.dev159","0.38.3.dev16","0.38.3.dev160","0.38.3.dev161","0.38.3.dev162","0.38.3.dev163","0.38.3.dev164","0.38.3.dev165","0.38.3.dev166","0.38.3.dev17","0.38.3.dev18","0.38.3.dev19","0.38.3.dev2","0.38.3.dev20","0.38.3.dev21","0.38.3.dev22","0.38.3.dev23","0.38.3.dev24","0.38.3.dev25","0.38.3.dev26","0.38.3.dev27","0.38.3.dev28","0.38.3.dev29","0.38.3.dev3","0.38.3.dev30","0.38.3.dev31","0.38.3.dev33","0.38.3.dev4","0.38.3.dev41","0.38.3.dev43","0.38.3.dev44","0.38.3.dev45","0.38.3.dev46","0.38.3.dev47","0.38.3.dev48","0.38.3.dev49","0.38.3.dev5","0.38.3.dev50","0.38.3.dev51","0.38.3.dev52","0.38.3.dev53","0.38.3.dev54","0.38.3.dev55","0.38.3.dev56","0.38.3.dev57","0.38.3.dev6","0.38.3.dev60","0.38.3.dev66","0.38.3.dev7","0.38.3.dev76","0.38.3.dev8","0.38.3.dev86","0.38.3.dev89","0.38.3.dev9","0.38.3.dev91","0.38.3.dev93","0.38.3.dev94","0.38.3.dev98","0.38.3.dev99","0.4.0","0.4.1","0.5.0","0.5.1","0.6.0","0.7.0","0.8.0","0.9.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/ouroboros-ai/PYSEC-2026-2857.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}