{"data":{"id":"e7b03438-7ee9-4f30-9304-167229d6dfd2","title":"CVE-2026-108759: mistral.rs 0.9.0 through 0.9.4 contains a link following vulnerability in mistralrs-code-exec that allows sandboxed…","summary":"mistral.rs versions 0.9.0 through 0.9.4 contain a link following flaw in mistralrs-code-exec. Sandboxed shell code can read and overwrite files outside the sandbox through symlinks, and attackers or prompt-injected agents can exploit this by naming symlinks as outputs or reusing sessions with symlinked input paths. Access runs with the server process's permissions.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108759","publishedAt":"2026-10-11T13:17:21.167Z","cveId":"CVE-2026-108759","cweIds":["CWE-59"],"cvssScore":"6.8","cvssSeverity":"medium","severity":"medium","attackType":["prompt_injection","other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["mistral.rs","mistralrs-code-exec"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"mistral.rs sandbox escape via symlinks in mistralrs-code-exec","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"epssCheckedAt":"2026-10-11T18:07:30.339Z","kevDateAdded":null,"advisoryAliases":["GHSA-fjjm-5mgr-r8vp"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-11T18:07:34.113Z","patchAvailable":null,"disclosureDate":"2026-10-11T13:17:21.167Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0051"]}}