๐Ÿ” CVE Alert

CVE-2026-66065

UNKNOWN 0.0

Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a .env (auto-loaded at import, with no review step). The CVE-2026-47211 fix added _UNTRUSTED_ENV_DENYLIST to stop an untrusted project-directory .env from redirecting execution, but it did not account for all keys. The backend config-home and MCP/plugin roots bypass the approval gate by pointing the nested agent, MCP servers, and plugin roster at attacker config. Other variables re-enable blocked local transports, replace sub-agent prompts, switch backends, and lower tool approval classes, further weakening the approval gate. This issue has been fixed in version 0.42.1.

CWE CWE-15 CWE-94
Vendor q00
Product ouroboros
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for q00 ouroboros

Be the first to know when new unknown vulnerabilities affecting q00 ouroboros are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Q00 / ouroboros
< 0.42.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Q00/ouroboros/security/advisories/GHSA-jv2h-4p9v-wf5w github.com: https://github.com/Q00/ouroboros/releases/tag/v0.42.1