MediumVulnerabilityLLM-specific
CVE-2026-108600: open-multi-agent link following flaw in file_write tool sandbox
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108600
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
open-multi-agent (@open-multi-agent/core) versions 1.5.0 through 1.21.2 contain a link following flaw in the file_write tool sandbox. An attacker can plant a dangling symlink in the workspace and use prompt injection to steer the agent into writing attacker-influenced content to any location the agent process can write, outside the workspace root.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- MediumCVE-2026-108670: JeecgBoot missing authorization in AiragPromptsControllerSimilar attack · NVD/CVE Database
- MediumCVE-2026-108599: phi symlink escape in permission gate allows writes outside workspaceSimilar attack · NVD/CVE Database
- MediumCVE-2026-108597: Cohere Python SDK path traversal in model archive extractionSimilar attack · NVD/CVE Database
- MediumCVE-2026-108592: mini-swe-agent information exposure in BubblewrapEnvironment sandboxSimilar attack · NVD/CVE Database
- MediumCVE-2026-108583: zotero-mcp server-side request forgery via zotero_add_by_urlSimilar attack · NVD/CVE Database