What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). Both are agent permission-boundary escapes chaining prompt injection to unapproved file writes.
Why it matters
Sandbox permission-gate escapes in a coding-agent framework are the mechanism by which prompt injection escalates into real file-system impact; low severity because the attacker must already steer the agent.
Attack vector
Two sandbox-escape flaws: agent_spawn does not validate the supplied workdir so spawned sub-agents escape workspace_only_writes/readonly; and the permission gate resolves symlinks only lexically, letting a malicious repo commit symlinks pointing outside the workspace so prompt-injected writes hit external files.
Affected systems
github.com/pulseaiclub/phi 0.3.0–0.28.4 (agent_spawn workdir) and 0.1.1–0.28.4 (lexical-only symlink path check)
Mitigation
Upgrade past 0.28.4 and validate workdir + resolve paths against real targets (not lexical strings). See VulnCheck advisories.