CVE-2026-88062: CWE-94: Improper Control of Generation of Code ('Code Injection') in diegosouzapw OmniRoute
OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency check before execFileSync executed the selected interpreter and arguments. The same request called refreshAgentCache, and resolveVersionProbe accepted the matched command before the execFileSync sink ran it. The tokenizeVersionCommand function and DISALLOWED_VERSION_COMMAND_CHARS filter rejected a limited set of shell metacharacters but still allowed interpreter evaluation arguments. The isAuthenticated function relied on isAuthRequired, which accepted anonymous requests when requireLogin was false, while api/acp/ was absent from LOCAL_ONLY_API_PREFIXES and SPAWN_CAPABLE_PREFIXES. With requireLogin=false or during a fresh-instance bootstrap window, a remote anonymous request could supply an interpreter evaluation argument and execute arbitrary code in the server container. With requireLogin=true and a configured management password, exploitation instead required a management session or management-scoped API key. No fixed version is available as of this review.
AI Analysis
Technical Summary
OmniRoute, an open-source AI gateway, suffers from a code injection vulnerability (CWE-94) in versions 3.8.49 and earlier. The POST /api/acp/agents endpoint accepts binary and versionCommand parameters that are only filtered by a limited set of disallowed shell metacharacters, allowing interpreter evaluation arguments to pass. The isAuthenticated function permits anonymous access when requireLogin is false, and the API path is not restricted by LOCAL_ONLY_API_PREFIXES or SPAWN_CAPABLE_PREFIXES. This combination allows remote attackers to execute arbitrary code via crafted requests that invoke execFileSync with attacker-controlled arguments. When requireLogin is true, exploitation requires a management session or API key. No patch or fixed version is available as of the review date.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code within the server container hosting OmniRoute, potentially leading to full system compromise. The vulnerability is exploitable without authentication if requireLogin is disabled or during initial bootstrap, increasing risk. With requireLogin enabled, exploitation requires elevated privileges via management sessions or API keys.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should verify their configuration to ensure requireLogin is enabled to reduce exposure. Avoid exposing the vulnerable API endpoint to untrusted networks. Monitor vendor advisories for updates and patches addressing this issue.
CVE-2026-88062: CWE-94: Improper Control of Generation of Code ('Code Injection') in diegosouzapw OmniRoute
Description
OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency check before execFileSync executed the selected interpreter and arguments. The same request called refreshAgentCache, and resolveVersionProbe accepted the matched command before the execFileSync sink ran it. The tokenizeVersionCommand function and DISALLOWED_VERSION_COMMAND_CHARS filter rejected a limited set of shell metacharacters but still allowed interpreter evaluation arguments. The isAuthenticated function relied on isAuthRequired, which accepted anonymous requests when requireLogin was false, while api/acp/ was absent from LOCAL_ONLY_API_PREFIXES and SPAWN_CAPABLE_PREFIXES. With requireLogin=false or during a fresh-instance bootstrap window, a remote anonymous request could supply an interpreter evaluation argument and execute arbitrary code in the server container. With requireLogin=true and a configured management password, exploitation instead required a management session or management-scoped API key. No fixed version is available as of this review.
CVSS v4.0
Score 9.5critical
Affected software
diegosouzapw
OmniRoute
pkg:github/diegosouzapw/OmniRouteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OmniRoute, an open-source AI gateway, suffers from a code injection vulnerability (CWE-94) in versions 3.8.49 and earlier. The POST /api/acp/agents endpoint accepts binary and versionCommand parameters that are only filtered by a limited set of disallowed shell metacharacters, allowing interpreter evaluation arguments to pass. The isAuthenticated function permits anonymous access when requireLogin is false, and the API path is not restricted by LOCAL_ONLY_API_PREFIXES or SPAWN_CAPABLE_PREFIXES. This combination allows remote attackers to execute arbitrary code via crafted requests that invoke execFileSync with attacker-controlled arguments. When requireLogin is true, exploitation requires a management session or API key. No patch or fixed version is available as of the review date.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code within the server container hosting OmniRoute, potentially leading to full system compromise. The vulnerability is exploitable without authentication if requireLogin is disabled or during initial bootstrap, increasing risk. With requireLogin enabled, exploitation requires elevated privileges via management sessions or API keys.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should verify their configuration to ensure requireLogin is enabled to reduce exposure. Avoid exposing the vulnerable API endpoint to untrusted networks. Monitor vendor advisories for updates and patches addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-09T21:22:45.434Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa3080491cc7f38489f6538
Added to database: 09/10/2026, 19:41:56 UTC
Last enriched: 09/10/2026, 19:52:18 UTC
Last updated: 09/10/2026, 22:12:32 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.