A vulnerability has been found in Q00 Ouroboros up to 0.38.x and classified as critical. Affected by this issue is some unknown functionality of the component Environment Variable Loading. The manipulation of the argument OUROBOROS_CLI_PATH/OPENCODE_CLI_PATH leads to os command injection.

This vulnerability is documented as CVE-2026-47211. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.