Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-108599: phi symlink escape in permission gate allows writes outside workspace

Identifier
CVE-2026-108599
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

phi versions 0.1.1 through 0.28.4 contain an improper link resolution flaw (CVE-2026-108599). Malicious repositories can commit symlinks that point outside the workspace, bypassing workspace_only_writes because the permission gate performs only lexical path checks. Prompt injection can then make the write tool write attacker-influenced content to external files without approval.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.