OmniRoute ACP Custom-Agent Remote Code Execution #8850
|
Hello OmniRoute Team, I hope you are doing well. I am following up on the OmniRoute ACP Custom-Agent Remote Code Execution vulnerability that I reported approximately three weeks ago. I understand that the issue has now been fixed, and I appreciate your team’s efforts in addressing it. Since the vulnerability had remote code execution impact, I wanted to ask whether your team would be open to requesting a CVE identifier for it. I would also be interested in coordinating a responsible public disclosure once you consider it appropriate. Please let me know your thoughts, as well as whether there is a preferred process or disclosure timeline that I should follow. I would be happy to provide any additional technical details needed for the CVE request. Thank you again for your time and for addressing the issue. |
Replies: 1 comment 1 reply
|
Thanks for reporting this responsibly, @c111mb3r. The ACP custom-agent process-spawn path was fixed in PR #7966 and shipped in v3.8.49. For CVE assignment and coordinated disclosure, please use the private GitHub Security Advisory form linked from |
Thanks for reporting this responsibly, @c111mb3r. The ACP custom-agent process-spawn path was fixed in PR #7966 and shipped in v3.8.49.
/api/acp/agentsis now classified as local-only, so loopback enforcement runs before authentication.For CVE assignment and coordinated disclosure, please use the private GitHub Security Advisory form linked from
SECURITY.md: https://github.com/diegosouzapw/OmniRoute/security/advisories/new. There is no published advisory or allocated CVE for this report yet, so that private thread is the right place to coordinate the timeline and request a CVE without adding exploit detail here.