What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). Same family as the Phi symlink escape (CVE-2026-108599) — lexical-only path safety in a file-write tool.
Why it matters
Sandbox path-escape in an agent file tool; niche package, no confirmed in-the-wild exploit, kept for precision.
Attack vector
The file_write sandbox follows a dangling symlink planted inside the workspace instead of confining to the workspace root, so prompt-injected agents write attacker-influenced content outside the sandbox (CWE-59).
Affected systems
@open-multi-agent/core 1.5.0 through 1.21.2 (file-write tool sandbox)
Mitigation
Upgrade past 1.21.2; open files with O_NOFOLLOW and verify resolved real paths. See VulnCheck advisory.