Threat reportVulnerabilityTL-2026-1921
Odysseus AI Workspace Remote Code Execution via Authorization Bypass — GHSA-xwhc-f36c-v5vm (CVSS 9.9)
Odysseus AI Workspace Remote Code Execution via (TL-2026-1921) is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-08-06. It has no confirmed attribution, affects Odysseus AI Workspace, maps to 12 MITRE ATT&CK techniques (T1005, T1021, T1048), and is covered by 9 detection rules and 6 indicators of compromise.
- CVSS
- 9.9/10Critical
- CVEs
- 0None referenced
- Techniques
- 12MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 6Indicators of compromise
Key facts for TL-2026-1921
- Threat ID
- TL-2026-1921
- Severity
- CRITICAL
- CVSS
- 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Motivation
- UNKNOWN
- Target sectors
- technology, open-source-software, individuals, startups
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 6
Malware and tooling in Odysseus AI Workspace Remote Code Execution via
Malware and tooling: PewDiePie, Python
How Odysseus AI Workspace Remote Code Execution via works
A critical vulnerability in Odysseus, a privacy-focused AI workspace for LLM interaction, allows any authenticated non-admin user to execute arbitrary OS commands with the privileges of the Odysseus process by smuggling an admin-only shell action onto a scheduled task across two ordinary API requests. Fixed in version 1.0.2. Exposed data includes user password hashes, TOTP secrets, stored provider API keys, database contents, and SSH keys to remote machines.
Odysseus is a multi-user, privacy-focused self-hosted AI workspace created by PewDiePie (Felix Kjellberg, handle archdaemon) providing chat with LLMs, autonomous agents, tools, model serving, email, and research capabilities. The project launched on May 31, 2026, rapidly accumulating over 62,000 GitHub stars and 300+ contributors. The threat model (THREAT_MODEL.md) defines a clear role-based access control (RBAC) boundary: shell and Python execution, file read/write, email, MCP tools, and vault access are admin-only capabilities. A scheduled tasks mechanism allows users to create jobs that run on schedules, webhooks, or manual triggers, with built-in actions including run_local, run_script, and ssh_command that execute shell commands on the host via Python's subprocess.run(script, shell=True).
Manifold Security discovered a critical authorization bypass allowing any authenticated non-admin user to execute arbitrary OS commands. The core defect was a state desynchronization across three code paths: the create gate in routes/task_routes.py checked whether the incoming request's task_type was "action" and the action was admin-only; the update gate checked whether the incoming request included an action field; and the scheduler dispatch in src/task_scheduler.py checked the stored task.task_type. No single code path asked whether the task as it stood would run a shell command — each evaluated only the fields the request happened to contain. By splitting the attack into two API calls, an attacker could assemble a privileged job from two individually unprivileged requests, with neither gate recognizing the full picture.
The first request creates a task with task_type set to "research" (a benign type bypassing the create gate) but attaches the admin-only run_local action. The create gate saw task_type="research" — not "action" — and never inspected the action field, persisting it to the database regardless. The second request updates only the task_type to "action" via a PUT endpoint. The update gate defaulted the action field to None in the request body, so the guard if req.action is not None evaluated as false and the admin privilege check never ran. With both modifications complete, the task carried task_type="action" (from the update) and action="run_local" (persisted from creation). Triggering the task via POST /api/tasks/{id}/run caused the scheduler to dispatch based on the stored task_type, executing arbitrary shell commands via subprocess.run(script, shell=True) with the privileges of the Odysseus process (uid 1000 in Docker).
Commands executed as the odysseus user with no sandboxing, filesystem confinement, or egress filtering. The project's own THREAT_MODEL.md acknowledges the absence of shell/filesystem sandboxing as a known gap. The process holds all sensitive application data: user password hashes (bcrypt) and TOTP secrets, stored provider AI API keys, the full application database, and SSH keys that Odysseus uses to access remote managed machines. On any instance with self-service signup enabled or more than one user, compromising a single non-admin account becomes a full foothold — attackers gain API keys to spend, a mailbox to send from, SSH keys to managed machines, and a scheduler mechanism for persistence. There is no evidence the issue was exploited before the fix.
The project consolidated five independent reports of the same defect. Manifold Security (Francisco Rosales) disclosed with a full Docker Compose PoC on June 8, 2026. The fix merged on July 5, 2026 in PR #5235 (commit 2826dcfc), binding the authorization decision to the task's effective final (task_type, action) pair, revalidating persisted state at every boundary (resume, manual-run, webhook, and scheduler dispatch), and pausing existing privileged rows owned by non-admin users rather than executing them. Odysseus has had additional security findings including CVE-2026-70619 (broken access control in embeddings endpoint, CVSS 8.8), CVE-2026-70620 (SSRF in embeddings endpoint, CVSS 6.8), and multiple prompt injection vulnerabilities (fixed in PR #3383 via untrusted context wrapping). These findings underscore the security challenges of AI-assisted development at scale — the project was reportedly "vibe coded" (AI-generated from scratch), contributing to authorization gaps across the codebase.
MITRE ATT&CK techniques used in TL-2026-1921
Collection
Lateral Movement
Exfiltration
T1048 Exfiltration Over Alternative Protocol
Execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Command and Control
T1071 Application Layer Protocol
Initial Access
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Credential Access
T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Affected products and versions in Odysseus AI Workspace Remote Code Execution via
- Odysseus — AI Workspace
Vulnerable versions: through 1.0.1; before commit 2826dcfc
Fixed in: 1.0.2 (commit 2826dcfc)
Remediation for Odysseus AI Workspace Remote Code Execution via
Patches
- Upgrade to Odysseus version 1.0.2 or cherry-pick commit 2826dcfc on the dev branch
Immediate actions
- Upgrade Odysseus to version 1.0.2 (commit 2826dcfc) immediately on all instances
- Audit all existing tasks across all user accounts for hidden admin-only actions
- Rotate all credentials stored in Odysseus: provider API keys, SSH keys, user passwords, TOTP secrets
Workarounds
- Disable self-service user registration if not operationally required
- Review all non-admin user accounts and remove unused or suspicious accounts
- Restrict outbound network access from Odysseus containers to only required LLM API endpoints
- Monitor API logs for the task-type-flip pattern: POST /api/tasks followed by PUT /api/tasks/{id} changing task_type from non-admin to action, followed by POST /api/tasks/{id}/run
Longer-term hardening
- Implement authorization revalidation at every execution boundary (create, update, resume, manual-run, webhook, scheduler dispatch)
- Deploy runtime monitoring to detect application processes spawning child shell processes (/bin/sh) as a detection signal
- Add network egress filtering and filesystem sandboxing for Odysseus containers (e.g., seccomp, AppArmor, read-only root filesystem)
- Maintain a coordinated vulnerability disclosure (CVD) program with GitHub Security Advisories enabled
- Conduct a full security audit of the API authorization middleware for state-desynchronization patterns
Weaknesses (CWE) in Odysseus AI Workspace Remote Code Execution via
Timeline of Odysseus AI Workspace Remote Code Execution via
- Odysseus AI Workspace publicly announced by PewDiePie (Felix Kjellberg) via YouTube launch video; repository reaches 1.5M+ views on launch video in 24 hours and 62K+ GitHub stars
- Multiple prompt injection vulnerabilities reported in Odysseus (PR #3383); GitHub Security Advisories not yet enabled on the repository; community contributors begin source code audits
- Manifold Security (Francisco Rosales) independently discovers the RCE authorization bypass vulnerability and reports it with a full Docker Compose reproduction PoC
- Within 8 days of initial disclosure, four other independent researchers reported the same RCE authorization bypass vulnerability to Odysseus maintainers, confirming the bug's discoverability
- Additional vulnerabilities disclosed: CVE-2026-70619 (broken access control in /api/embeddings/endpoint, CVSS 8.8) and CVE-2026-70620 (SSRF in same endpoint, CVSS 6.8); both assigned by VulnCheck
- Odysseus version 1.0.2 released containing the RCE fix (commit 9844a2f9, including fix commit 2826dcfc); default branch updated with the security patch
- Fix merged in PR #5235 (commit 2826dcfc): authorization decision bound to the task's effective final (task_type, action) pair; persistent state revalidated at resume, manual-run, webhook, and scheduler dispatch boundaries; existing privileged non-admin rows paused
- GitHub Security Advisory GHSA-xwhc-f36c-v5vm drafted and assessed as Critical (CVSS 9.9); pending CVE assignment from GitHub Security Lab
- Manifold Security publishes full technical disclosure blog post detailing the exploit chain, authorization bypass mechanism, impact analysis, and fix guidance
- The Hacker News publishes ThreatsDay coverage bringing the vulnerability to broad public attention alongside other security news
Sources cited for Odysseus AI Workspace Remote Code Execution via
- Manifold Security — Anyone with an account could run commands on Odysseus (CVSS 9.9)
- The Hacker News — ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
- GitHub Advisory — GHSA-xwhc-f36c-v5vm (Odysseus RCE)
- GitHub PR #5235 — Fix: Gate task execution authorization (cookbook_serve and shell actions)
- GitHub Issue #5233 — Authorization revalidation for scheduled tasks
- Odysseus THREAT_MODEL.md — Security Architecture and RBAC
- Odysseus — GitHub Repository (odysseus-dev/odysseus)
- CVE-2026-70619 / CVE-2026-70620 — Odysseus Embedding Endpoint Vulnerabilities
- GitHub PR #3383 — Security: Harden agent path against prompt injection
- GitHub Issue #1058 — Reduce agent blast radius: sandbox tool execution
- GitHub Issue #245 — Enable GitHub Security Advisories for private disclosure
- GitHub PR #1629 — Fix(agent): wrap non-native tool results as untrusted data
Detection coverage for TL-2026-1921
As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1921 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.