<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:29:23.417963+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-367109</id>
    <title>EUVD-2026-367109</title>
    <updated>2026-10-04T07:29:23.465460+00:00</updated>
    <content>EUVD-2026-367109</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-367109"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-88062</id>
    <title>fkie_cve-2026-88062</title>
    <updated>2026-10-04T07:29:23.465498+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency check before execFileSync executed the selected interpreter and arguments. The same request called refreshAgentCache, and resolveVersionProbe accepted the matched command before the execFileSync sink ran it. The tokenizeVersionCommand function and DISALLOWED_VERSION_COMMAND_CHARS filter rejected a limited set of shell metacharacters but still allowed interpreter evaluation arguments. The isAuthenticated function relied on isAuthRequired, which accepted anonymous requests when requireLogin was false, while api/acp/ was absent from LOCAL_ONLY_API_PREFIXES and SPAWN_CAPABLE_PREFIXES. With requireLogin=false or during a fresh-instance bootstrap window, a remote anonymous request could supply an interpreter evaluation argument and execute arbitrary code in the server container. With requireLogin=true and a configured management password, exploitation instead required a management session or management-scoped API key. No fixed version is available as of this review.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-88062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hf57-cqmx-p4gr</id>
    <title>GHSA-hf57-cqmx-p4gr — OmniRoute ACP Custom-Agent Remote Code Execution (RCE)</title>
    <updated>2026-10-04T07:29:23.465537+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: omniroute</p>
<p>## 2. Summary</p>
<p>`POST /api/acp/agents` registers a custom ACP agent. The endpoint accepts user-controlled
`binary` and `versionCommand` values. After saving the custom agent, the same request calls
`refreshAgentCache()`, which triggers agent version detection. The version probe eventually runs:</p>
<p>```ts
execFileSync(probe.command, probe.args, ...)
```</p>
<p>The only validation is `resolveVersionProbe(binary, versionCommand, true)`, which checks that the
first token of `versionCommand` matches the request-provided `binary`. Because `binary` is also
attacker-controlled, an attacker can submit:</p>
<p>```json
{
  "binary": "node",
  "versionCommand": "node -e \"...arbitrary JavaScript...\""
}
```</p>
<p>This executes arbitrary Node.js code inside the server container, and that code can execute OS
commands via `child_process.execSync()`.</p>
<p>When `requireLogin=false`, `isAuthenticated()` treats anonymous requests as authenticated. At the
same time, `/api/acp/` is not included in `LOCAL_ONLY_API_PREFIXES` or `SPAWN_CAPABLE_PREFIXES`, so
the endpoint is not blocked by the LOCAL_ONLY policy before reaching the anonymous allow branch.
As a result, a remote anonymous attacker can execute commands inside the OmniRoute container with a
single HTTP request.</p>
<p>## 3. Preconditions</p>
<p>The unauthenticated exploit is reachable in either of the following scenarios:</p>
<p>1. The target instance has `requireLogin=false`. This is the primary scenario covered by this
   report and by the reproduction steps below.
2. A fresh in…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hf57-cqmx-p4gr"/>
  </entry>
</feed>
