Intel

AIKIDO-2026-501705

ouroboros-ai is vulnerable to Code Injection

Code InjectionGHSA-wvgf-hr9x-v3g6 Published 2 days ago

78

High Risk

This Affects:

PYTHONouroboros-ai
0.42.0 - 0.50.7
Fixed in 0.50.8
Are you affected? Scan for Free

TL;DR

The ooo bridge extensions read the OUROBOROS_CLI environment variable and use its value directly as the executable command to run. Earlier hardening added execution-routing variables to an untrusted-environment denylist but omitted the suffix-less OUROBOROS_CLI alias, so a project-local .env file could still set it. When a user runs an ooo command inside a cloned repository, the supplied path executes with the user's privileges, working directory, and environment. The fix adds OUROBOROS_CLI to the untrusted-environment denylist while keeping trusted shell and home-directory sources working.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have configured the gjc or pi runtime bridge and run ooo commands inside untrusted repositories that can ship a project-local .env file.

Background info

ouroboros-ai is vulnerable to Code Injection in versions 0.42.0 - 0.50.7.

How to fix this

Upgrade the ouroboros-ai library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform