{"data":{"id":"d8b61e6f-b503-4ae6-af21-b0b4dcf32466","title":"CVE-2026-108599: phi 0.1.1 through 0.28.4 contains an improper link resolution vulnerability that allows malicious repositories to…","summary":"phi versions 0.1.1 through 0.28.4 contain an improper link resolution flaw (CVE-2026-108599). Malicious repositories can commit symlinks that point outside the workspace, bypassing workspace_only_writes because the permission gate performs only lexical path checks. Prompt injection can then make the write tool write attacker-influenced content to external files without approval.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108599","publishedAt":"2026-10-10T19:16:58.487Z","cveId":"CVE-2026-108599","cweIds":["CWE-59"],"cvssScore":"4.7","cvssSeverity":"medium","severity":"medium","attackType":["prompt_injection","other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["phi"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"phi symlink escape in permission gate allows writes outside workspace","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"local","attackComplexity":"high","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"epssCheckedAt":"2026-10-11T00:10:11.203Z","kevDateAdded":null,"advisoryAliases":["GHSA-mhj6-8rvv-3grj"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-11T00:10:14.973Z","patchAvailable":null,"disclosureDate":"2026-10-10T19:16:58.487Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0051"]}}