{"data":{"id":"cd92e600-723e-4345-bd68-6ebcea1cfb30","title":"CVE-2026-108600: open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the…","summary":"open-multi-agent (@open-multi-agent/core) versions 1.5.0 through 1.21.2 contain a link following flaw in the file_write tool sandbox. An attacker can plant a dangling symlink in the workspace and use prompt injection to steer the agent into writing attacker-influenced content to any location the agent process can write, outside the workspace root.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108600","publishedAt":"2026-10-10T19:16:58.640Z","cveId":"CVE-2026-108600","cweIds":["CWE-59"],"cvssScore":"4.7","cvssSeverity":"medium","severity":"medium","attackType":["prompt_injection","other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["open-multi-agent","@open-multi-agent/core"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"open-multi-agent link following flaw in file_write tool sandbox","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"local","attackComplexity":"high","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"epssCheckedAt":"2026-10-11T00:10:11.208Z","kevDateAdded":null,"advisoryAliases":["GHSA-h42w-g3ch-rjjm"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-11T00:10:14.540Z","patchAvailable":null,"disclosureDate":"2026-10-10T19:16:58.640Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0051"]}}