Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H상세 설명
Summary
An authenticated, non-admin user can obtain arbitrary host-filesystem read/write (and host environment-secret disclosure) on an Omnigent runner by uploading an agent bundle whose os_env.cwd points outside any intended workspace (e.g. / or /home/<victim>). The cwd field is taken verbatim from the bundle with no validation, normalization, or boundary check anywhere in the spec pipeline.
This is a different sink from GHSA-jrrm-9hc7-2v3h (CWE-94, shared-agent bundle overwrite -> stdio MCP RCE). It shares the bundle-upload vector but is reached through the user's own session-scoped agent and is not addressed by that advisory's proposed shared-agent guard.
Preconditions
- Runner realizes a session-scoped uploaded bundle without
OMNIGENT_RUNNER_WORKSPACEset. When that env var is set (CLI- and host-launched sessions set it), the speccwdis overridden and the attack is neutralized — so this is deployment-gated, not universal. - Attacker is any authenticated user (no admin scope;
_require_useronly checks identity). No shared-agent overwrite needed.
Details (verified against code)
- Parse — no validation.
omnigent/spec/parser.py:696storescwd=str(cwd_raw)verbatim. Absolute paths (/,/etc),../.., etc. are all accepted. Thesandbox.typeis likewise author-chosen and"none"is legal. - Validate — cwd unconstrained.
omnigent/spec/validator.py_validate_os_envchecks only fork/scratch/egress combinations; it never referencescwd(the sole mention, line ~526, is a comment). No boundary is applied to the cwd itself. The boundary inserver/schemas.pyvalidates a caller-supplied workspace against the spec cwd (treating the author cwd as trusted) and only for host-launched sessions — it does not bound the cwd. - Sink.
omnigent/inner/os_env.py:890setscwd = Path(spec.cwd or os.getcwd()).resolve(strict=False)as the environment root;os_env.py:934doesshutil.copytree(src=cwd, ...)whenfork=true. All agent file/shell tools are bounded by_assert_within_cwd(os_env.py:1040), which checksresolved.relative_to(cwd)— but since cwd is attacker-controlled,cwd=/makes the entire host filesystem in-bounds for read and write;fork=truewithcwd=/home/victimcopies that tree into the agent-readable workspace. - Decisive gate.
omnigent/runner/resource_registry.py:648-654:cwd = default_cwdonly whenself._runner_workspace is not None or spec_os_env.cwd in (None, ".", "./"); otherwisecwd = spec_os_env.cwd(the attacker's absolute path). SoOMNIGENT_RUNNER_WORKSPACEis the only thing standing between the spec and the host FS — and it is an operational control, not an in-code guard. A code comment attool_dispatch.py:~4207claims cwd "is treated as a boundary at session-create time," which is not true on this path.
Attack path
- Authenticated user sends
POST /v1/sessions(multipart) with an agent bundle whoseconfig.yamlcontains:bash1os_env:2 cwd: "/" # or /home/<victim>, with fork: true for one-shot exfil3 sandbox: { type: none } - On a runner without
OMNIGENT_RUNNER_WORKSPACE, the agent'ssys_os_read/write/edit/shelltools now operate over the whole host filesystem, and (sandbox inactive) inherit the runner's full environment — exposing host secrets via e.g.sys_os_shell("env").
Impact
Arbitrary host-filesystem read/write and runner-environment secret disclosure, available to any authenticated user on an affected deployment. High severity (deployment-conditional).
Suggested fix
Add a control on the cwd field itself in omnigent/spec/_validate_os_env (and/or at parse): reject absolute paths and .. traversal, and require cwd to resolve within the runner workspace / an allow-listed root. Do not rely on OMNIGENT_RUNNER_WORKSPACE being set as the sole defense. Consider also disallowing bundle-author sandbox.type: none for server-realized (non-CLI) sessions.
Related
GHSA-jrrm-9hc7-2v3h (same bundle-upload vector, different sink; that fix does not cover this).
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
참고 자료 6
링크 내용 불러오는 중…