Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-108759: mistral.rs sandbox escape via symlinks in mistralrs-code-exec

Identifier
CVE-2026-108759
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

mistral.rs versions 0.9.0 through 0.9.4 contain a link following flaw in mistralrs-code-exec. Sandboxed shell code can read and overwrite files outside the sandbox through symlinks, and attackers or prompt-injected agents can exploit this by naming symlinks as outputs or reusing sessions with symlinked input paths. Access runs with the server process's permissions.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.