What happened
VulnCheck published CVE-2026-108759 (published 2026-10-11, CWE-59 link following; CVSS 4.0 v4 7.6 / v3.1 6.8) for mistral.rs 0.9.0-0.9.4: the code-exec sandbox's output/input handling follows symlinks outside the sandbox, giving sandboxed (often prompt-injected) code host filesystem access. Verified against NVD REST API.
Why it matters
mistral.rs is a widely used local/self-hosted LLM inference engine; code-exec is exposed to LLM output. A symlink-following sandbox escape gives a prompt-injected model read/write access to host files — model weights, configs, credentials — turning LLM tool output into host compromise in self-hosted AI deployments.
Attack vector
A prompt-injected agent or attacker names symlinks as sandbox outputs or reuses sessions with symlinked input paths, and the mistralrs-code-exec sandbox follows the links — letting the sandboxed code read and overwrite arbitrary host files with the server process's permissions.
Affected systems
mistral.rs 0.9.0 through 0.9.4 (mistralrs-code-exec)
Mitigation
Upgrade past 0.9.4, or avoid exposing code-exec to untrusted sessions; validate/deny symlinks and mount sandbox inputs read-only. Advisory: https://www.vulncheck.com/advisories/mistral-rs-0.9.0-through-0.9.4-sandbox-escape-via-symlink-following-in-mistralrs-code-exec