Skip to content
Discussion options

You must be logged in to vote

Thanks for reporting this responsibly, @c111mb3r. The ACP custom-agent process-spawn path was fixed in PR #7966 and shipped in v3.8.49. /api/acp/agents is now classified as local-only, so loopback enforcement runs before authentication.

For CVE assignment and coordinated disclosure, please use the private GitHub Security Advisory form linked from SECURITY.md: https://github.com/diegosouzapw/OmniRoute/security/advisories/new. There is no published advisory or allocated CVE for this report yet, so that private thread is the right place to coordinate the timeline and request a CVE without adding exploit detail here.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@c111mb3r
Comment options

Answer selected by diegosouzapw
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants