MediumVulnerabilityLLM-specific
CVE-2026-108599: phi symlink escape in permission gate allows writes outside workspace
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108599
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
phi versions 0.1.1 through 0.28.4 contain an improper link resolution flaw (CVE-2026-108599). Malicious repositories can commit symlinks that point outside the workspace, bypassing workspace_only_writes because the permission gate performs only lexical path checks. Prompt injection can then make the write tool write attacker-influenced content to external files without approval.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- MediumCVE-2026-108670: JeecgBoot missing authorization in AiragPromptsControllerSimilar attack · NVD/CVE Database
- MediumCVE-2026-108600: open-multi-agent link following flaw in file_write tool sandboxSimilar attack · NVD/CVE Database
- MediumCVE-2026-108597: Cohere Python SDK path traversal in model archive extractionSimilar attack · NVD/CVE Database
- MediumCVE-2026-108592: mini-swe-agent information exposure in BubblewrapEnvironment sandboxSimilar attack · NVD/CVE Database
- MediumCVE-2026-108583: zotero-mcp server-side request forgery via zotero_add_by_urlSimilar attack · NVD/CVE Database