MediumVulnerabilityLLM-specific
CVE-2026-108759: mistral.rs sandbox escape via symlinks in mistralrs-code-exec
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108759
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
mistral.rs versions 0.9.0 through 0.9.4 contain a link following flaw in mistralrs-code-exec. Sandboxed shell code can read and overwrite files outside the sandbox through symlinks, and attackers or prompt-injected agents can exploit this by naming symlinks as outputs or reusing sessions with symlinked input paths. Access runs with the server process's permissions.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- MediumCVE-2026-108756: Abilityai Trinity missing authorization in Telegram router binding operationsSimilar attack · NVD/CVE Database
- MediumCVE-2026-108575: BerriAI LiteLLM improper authorization in secret resolution via api_keySimilar attack · NVD/CVE Database
- MediumCVE-2026-108574: BerriAI LiteLLM authorization bypass in session spend log view via session_idSimilar attack · NVD/CVE Database
- MediumCVE-2026-108670: JeecgBoot missing authorization in AiragPromptsControllerSimilar attack · NVD/CVE Database
- MediumCVE-2026-108600: open-multi-agent link following flaw in file_write tool sandboxSimilar attack · NVD/CVE Database