Junglewise Threat Intelligence

CVE-2026-47211: Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior.

CVE-2026-47211 · Severity: high · CVSS 4 · Published 2026-08-03

Vendors: PyPI.

Executive brief

Ouroboros-ai is an AI-related development tool. A vulnerability exists where the tool automatically loads configuration settings from a local file within a project directory. If a user clones a malicious repository and runs Ouroboros commands, an attacker can execute arbitrary code on the user's system, potentially leading to a full system takeover.

Technical details

Ouroboros-ai is vulnerable to Remote Code Execution (RCE) due to an untrusted search path (CWE-426) and external control of system settings (CWE-15). The application automatically loads environment variables from a `.env` file in the current working directory. An attacker can craft a malicious repository containing a `.env` file that overrides execution-affecting variables like `OUROBOROS_CLI_PATH` or `OPENCODE_CLI_PATH` to point to a malicious script. When a user executes commands such as `ouroboros init`, the tool executes the attacker-supplied script instead of the intended binary. This has been patched in version 0.39.0 by implementing a denylist for sensitive environment variables in project-local configurations.

Affected products

  • Q00 ouroboros-ai < 0.39.0

Timeline

  • 2026-05-20: disclosed: Vulnerability reported to vendor
  • 2026-05-29: advisory: GitHub Advisory published
  • 2026-05-29: patched: Fixed in version 0.39.0

References

Related threats