CVE-2026-108599

medium

Description

phi 0.1.1 through 0.28.4 contains an improper link resolution vulnerability that allows malicious repositories to bypass workspace_only_writes by exploiting lexical-only path checks in the permission gate. Attackers can commit symlinks pointing outside the workspace and use prompt injection to make the write tool write attacker-influenced content to external files without approval.

References

https://www.vulncheck.com/advisories/phi-0.1.1-through-0.28.4-symlink-workspace-write-restriction-bypass

https://hackmd.io/@haind/phi-symlink-permission-boundary

https://github.com/pulseaiclub/phi/blob/5b3cb440a7c58115ef64283a737a43299f2805a4/internal/tools/writetool/write.go#L64-L68

https://github.com/pulseaiclub/phi/blob/5b3cb440a7c58115ef64283a737a43299f2805a4/internal/permission/gate.go#L106-L119

https://github.com/pulseaiclub/phi

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-96393

Details

Source: Mitre, NVD

Published: 2026-10-10

Updated: 2026-10-10

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:C/A:N

Severity: Medium

CVSS v3

Base Score: 4.7

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Severity: Medium

CVSS v4

Base Score: 5.7

Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00172