Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.4 Node.js & npm GHSA-hf57-cqmx-p4gr CVE-2026-88062

OmniRoute ACP Custom-Agent Endpoint Allows Remote Code Execution (CVE-2026-88062)

A code injection flaw in OmniRoute's ACP custom-agent endpoint lets attackers execute arbitrary code on the server. No fixed version is currently available.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

OmniRoute, an open-source AI gateway that exposes a single endpoint for multiple AI model providers, contains a critical code injection vulnerability (CVE-2026-88062, GHSA-hf57-cqmx-p4gr) in its custom ACP agent endpoint. The flaw allows execution of arbitrary code inside the server container and, depending on configuration, may be exploitable without authentication. As of this review, no fixed version has been released.

What Happened

In OmniRoute version 3.8.49 and earlier (and confirmed affected through 3.8.50), the POST /api/acp/agents endpoint accepts attacker-controlled 'binary' and 'versionCommand' values for custom ACP agents. These values pass through a 'self-consistency' check and the tokenizeVersionCommand function with its DISALLOWED_VERSION_COMMAND_CHARS filter before being executed via execFileSync. The filter blocks a limited set of shell metacharacters but does not block interpreter evaluation arguments, meaning a crafted versionCommand can still cause arbitrary code execution when the interpreter processes it.

Technical Cause

The same request that creates a custom agent also triggers refreshAgentCache, and the resolveVersionProbe function accepts the matched command before it reaches the execFileSync sink. The input filtering in tokenizeVersionCommand and DISALLOWED_VERSION_COMMAND_CHARS is incomplete: it rejects certain shell metacharacters but permits interpreter evaluation arguments, which an attacker can use to smuggle executable code into the command that execFileSync runs. This is classified as CWE-94, Improper Control of Generation of Code ('Code Injection').

Who Is Affected

Authentication requirements depend on configuration. The isAuthenticated function relies on isAuthRequired, which permits anonymous requests when requireLogin is set to false. Additionally, the 'api/acp/' path is absent from both LOCAL_ONLY_API_PREFIXES and SPAWN_CAPABLE_PREFIXES, meaning it is not restricted the way other sensitive endpoints are. As a result: with requireLogin=false, or during a fresh-instance bootstrap window, a remote anonymous attacker can exploit this issue. With requireLogin=true and a configured management password, exploitation instead requires a management session or a management-scoped API key.

Affected Versions

OmniRoute versions from 0 through 3.8.50 are affected, which includes 3.8.49 and earlier as stated in the advisory description. No fixed version has been published at the time of this review.

Fixes and Mitigation

No fixed version is currently available for this vulnerability. Site owners should treat this as an open issue and monitor the GitHub Security Advisory (GHSA-hf57-cqmx-p4gr) for updates on a patched release.

Recommended Action

Until a fix is released, operators running OmniRoute should ensure requireLogin is enabled and a management password is configured, since this raises the bar for exploitation from anonymous remote access to requiring a management session or management-scoped API key. Operators should also be aware of the fresh-instance bootstrap window, during which anonymous exploitation may still be possible even with requireLogin intended to be enabled, and should restrict network access to the /api/acp/agents endpoint where possible until a patch is available.

PatchBriefing score

6.4 / 10 · Medium

Official CVSS: 9.5

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

This vulnerability has a CVSS v4.0 base score of 9.5, reflecting a critical, remotely exploitable code execution flaw with no required privileges or user interaction under certain configurations and high impact to confidentiality, integrity, and availability. The PatchBriefing score of 6.4 accounts for this high severity base, plus additional weight for unauthenticated remote exploitability, no user interaction requirement, and the absence of a fix. The score is tempered by the lack of confirmed known exploitation, no observed public exploit code, and no EPSS-based exploitation probability data being available.

Affected versions

omniroute <= 3.8.50
vulnerable

Reported fixes

No fixed version is currently available for this vulnerability. Site owners should treat this as an open issue and monitor the GitHub Security Advisory (GHSA-hf57-cqmx-p4gr) for updates on a patched release.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
OmniRoute ACP Custom-Agent Endpoint Allows Remote Code Execution (CVE-2026-88062)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email