PT-2026-109741 · Open Multi Agent · Open-Multi-Agent

·

CVE-2026-108600

·

Publicado

2026-10-10

·

Atualizado

2026-10-10

CVSS v3.1

4.7

Média

VetorAV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the file write tool sandbox that allows attackers to create files outside the workspace root by using dangling symlinks. Attackers can plant a dangling symlink in the workspace and steer the agent via prompt injection to write attacker-influenced content anywhere the agent process can write.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-108600

Produtos afetados

Open-Multi-Agent