VYPR
Medium severity4.4NVD Advisory· Published Oct 11, 2026

CVE-2026-108751

CVE-2026-108751

Description

MoAI-ADK through 3.1.2 contains an improper link resolution vulnerability in the moai init template deployer that allows malicious repositories to overwrite files outside the project via a symlinked .moai-tmp staging path. Attackers can commit a symlink such as .claude/settings.json.moai-tmp so atomicWriteFile truncates and overwrites victim-writable files with MoAI template content.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.