Vulnerability  ·  2026-10-11

open-multi-agent file_write dangling-symlink escape lets prompt-injected agents write outside the workspace (CVSS 4.7)

VulnerabilityLow impactGlobalCVE-2026-108600
Verified via NVD REST API (published 2026-10-10, VulnCheck). Same family as the Phi symlink escape (CVE-2026-108599) — lexical-only path safety in a file-write tool.
Sandbox path-escape in an agent file tool; niche package, no confirmed in-the-wild exploit, kept for precision.
The file_write sandbox follows a dangling symlink planted inside the workspace instead of confining to the workspace root, so prompt-injected agents write attacker-influenced content outside the sandbox (CWE-59).
@open-multi-agent/core 1.5.0 through 1.21.2 (file-write tool sandbox)
Upgrade past 1.21.2; open files with O_NOFOLLOW and verify resolved real paths. See VulnCheck advisory.
NVD CVE-2026-108600NVD REST APIVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →