Medium severity4.7NVD Advisory· Published Oct 10, 2026
CVE-2026-108600
CVE-2026-108600
Description
open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the file_write tool sandbox that allows attackers to create files outside the workspace root by using dangling symlinks. Attackers can plant a dangling symlink in the workspace and steer the agent via prompt injection to write attacker-influenced content anywhere the agent process can write.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 1.5.0 - 1.21.2
Patches
Vulnerability mechanics
References
4- github.com/open-multi-agent/open-multi-agent/blob/6ec5498643c7e431aa66751f17f47a529e7f927c/packages/core/src/tool/built-in/file-write.tsnvd
- github.com/open-multi-agent/open-multi-agent/blob/6ec5498643c7e431aa66751f17f47a529e7f927c/packages/core/src/tool/built-in/path-safety.tsnvd
- hackmd.io/@haind/open-multi-agent-file-write-dangling-symlink-escapenvd
- www.vulncheck.com/advisories/open-multi-agent-1.5.0-through-1.21.2-sandbox-escape-via-file-write-dangling-symlinknvd
News mentions
0No linked articles in our index yet.