Vulnerability  ·  2026-10-11

Phi agent framework: sub-agent workdir + symlink bypasses of workspace_only_writes permission gate (CVSS 5.3 / 4.7)

VulnerabilityLow impactGlobalCVE-2026-108595
Verified via NVD REST API (published 2026-10-10, VulnCheck). Both are agent permission-boundary escapes chaining prompt injection to unapproved file writes.
Sandbox permission-gate escapes in a coding-agent framework are the mechanism by which prompt injection escalates into real file-system impact; low severity because the attacker must already steer the agent.
Two sandbox-escape flaws: agent_spawn does not validate the supplied workdir so spawned sub-agents escape workspace_only_writes/readonly; and the permission gate resolves symlinks only lexically, letting a malicious repo commit symlinks pointing outside the workspace so prompt-injected writes hit external files.
github.com/pulseaiclub/phi 0.3.0–0.28.4 (agent_spawn workdir) and 0.1.1–0.28.4 (lexical-only symlink path check)
Upgrade past 0.28.4 and validate workdir + resolve paths against real targets (not lexical strings). See VulnCheck advisories.
NVD CVE-2026-108595NVD CVE-2026-108599VulnCheck advisories
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →