PT-2026-109741 · Open Multi Agent · Open-Multi-Agent

·

CVE-2026-108600

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the file write tool sandbox that allows attackers to create files outside the workspace root by using dangling symlinks. Attackers can plant a dangling symlink in the workspace and steer the agent via prompt injection to write attacker-influenced content anywhere the agent process can write.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-108600

Affected Products

Open-Multi-Agent