CVE-2026-62674
Omnigent Agent Command Injection Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An authenticated user with edit access to an Omnigent session can replace a shared agent, leading to the execution of attacker-controlled commands with the runner process's permissions, potentially exposing sensitive data and internal services. This vulnerability impacts AI agent orchestration and data security.