Medium · 6.4 Node.js & npm GHSA-hf57-cqmx-p4gr CVE-2026-88062
OmniRoute ACP Custom-Agent Endpoint Allows Remote Code Execution (CVE-2026-88062)
A code injection flaw in OmniRoute's ACP custom-agent endpoint lets attackers execute arbitrary code on the server. No fixed version is currently available.
AI summary
OmniRoute, an open-source AI gateway that exposes a single endpoint for multiple AI model providers, contains a critical code injection vulnerability (CVE-2026-88062, GHSA-hf57-cqmx-p4gr) in its custom ACP agent endpoint. The flaw allows execution of arbitrary code inside the server container and, depending on configuration, may be exploitable without authentication. As of this review, no fixed version has been released.
What Happened
In OmniRoute version 3.8.49 and earlier (and confirmed affected through 3.8.50), the POST /api/acp/agents endpoint accepts attacker-controlled 'binary' and 'versionCommand' values for custom ACP agents. These values pass through a 'self-consistency' check and the tokenizeVersionCommand function with its DISALLOWED_VERSION_COMMAND_CHARS filter before being executed via execFileSync. The filter blocks a limited set of shell metacharacters but does not block interpreter evaluation arguments, meaning a crafted versionCommand can still cause arbitrary code execution when the interpreter processes it.
Technical Cause
The same request that creates a custom agent also triggers refreshAgentCache, and the resolveVersionProbe function accepts the matched command before it reaches the execFileSync sink. The input filtering in tokenizeVersionCommand and DISALLOWED_VERSION_COMMAND_CHARS is incomplete: it rejects certain shell metacharacters but permits interpreter evaluation arguments, which an attacker can use to smuggle executable code into the command that execFileSync runs. This is classified as CWE-94, Improper Control of Generation of Code ('Code Injection').
Who Is Affected
Authentication requirements depend on configuration. The isAuthenticated function relies on isAuthRequired, which permits anonymous requests when requireLogin is set to false. Additionally, the 'api/acp/' path is absent from both LOCAL_ONLY_API_PREFIXES and SPAWN_CAPABLE_PREFIXES, meaning it is not restricted the way other sensitive endpoints are. As a result: with requireLogin=false, or during a fresh-instance bootstrap window, a remote anonymous attacker can exploit this issue. With requireLogin=true and a configured management password, exploitation instead requires a management session or a management-scoped API key.
Affected Versions
OmniRoute versions from 0 through 3.8.50 are affected, which includes 3.8.49 and earlier as stated in the advisory description. No fixed version has been published at the time of this review.
Fixes and Mitigation
No fixed version is currently available for this vulnerability. Site owners should treat this as an open issue and monitor the GitHub Security Advisory (GHSA-hf57-cqmx-p4gr) for updates on a patched release.
Recommended Action
Until a fix is released, operators running OmniRoute should ensure requireLogin is enabled and a management password is configured, since this raises the bar for exploitation from anonymous remote access to requiring a management session or management-scoped API key. Operators should also be aware of the fresh-instance bootstrap window, during which anonymous exploitation may still be possible even with requireLogin intended to be enabled, and should restrict network access to the /api/acp/agents endpoint where possible until a patch is available.
PatchBriefing score
6.4 / 10 · Medium
Official CVSS: 9.5
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
This vulnerability has a CVSS v4.0 base score of 9.5, reflecting a critical, remotely exploitable code execution flaw with no required privileges or user interaction under certain configurations and high impact to confidentiality, integrity, and availability. The PatchBriefing score of 6.4 accounts for this high severity base, plus additional weight for unauthenticated remote exploitability, no user interaction requirement, and the absence of a fix. The score is tempered by the lack of confirmed known exploitation, no observed public exploit code, and no EPSS-based exploitation probability data being available.
Affected versions
- omniroute <= 3.8.50
- vulnerable
Reported fixes
No fixed version is currently available for this vulnerability. Site owners should treat this as an open issue and monitor the GitHub Security Advisory (GHSA-hf57-cqmx-p4gr) for updates on a patched release.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email