PT-2026-109741 · Open Multi Agent · Open-Multi-Agent
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N |
open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the file write tool sandbox that allows attackers to create files outside the workspace root by using dangling symlinks. Attackers can plant a dangling symlink in the workspace and steer the agent via prompt injection to write attacker-influenced content anywhere the agent process can write.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open-Multi-Agent