Vulnerability  ·  2026-10-12

mistral.rs mistralrs-code-exec sandbox escape via symlinks → read/overwrite files with server permissions (CVSS 6.8)

VulnerabilityHigh impactGlobalCVE-2026-108759
VulnCheck published CVE-2026-108759 (published 2026-10-11, CWE-59 link following; CVSS 4.0 v4 7.6 / v3.1 6.8) for mistral.rs 0.9.0-0.9.4: the code-exec sandbox's output/input handling follows symlinks outside the sandbox, giving sandboxed (often prompt-injected) code host filesystem access. Verified against NVD REST API.
mistral.rs is a widely used local/self-hosted LLM inference engine; code-exec is exposed to LLM output. A symlink-following sandbox escape gives a prompt-injected model read/write access to host files — model weights, configs, credentials — turning LLM tool output into host compromise in self-hosted AI deployments.
A prompt-injected agent or attacker names symlinks as sandbox outputs or reuses sessions with symlinked input paths, and the mistralrs-code-exec sandbox follows the links — letting the sandboxed code read and overwrite arbitrary host files with the server process's permissions.
mistral.rs 0.9.0 through 0.9.4 (mistralrs-code-exec)
Upgrade past 0.9.4, or avoid exposing code-exec to untrusted sessions; validate/deny symlinks and mount sandbox inputs read-only. Advisory: https://www.vulncheck.com/advisories/mistral-rs-0.9.0-through-0.9.4-sandbox-escape-via-symlink-following-in-mistralrs-code-exec
NVD CVE-2026-108759VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →