Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-108600: open-multi-agent link following flaw in file_write tool sandbox

Identifier
CVE-2026-108600
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

open-multi-agent (@open-multi-agent/core) versions 1.5.0 through 1.21.2 contain a link following flaw in the file_write tool sandbox. An attacker can plant a dangling symlink in the workspace and use prompt injection to steer the agent into writing attacker-influenced content to any location the agent process can write, outside the workspace root.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.