CVE-2026-108599
Received Received - Intake

Improper Link Resolution in phi Allows Workspace Bypass via Symlink Exploitation

Vulnerability report for CVE-2026-108599, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

phi 0.1.1 through 0.28.4 contains an improper link resolution vulnerability that allows malicious repositories to bypass workspace_only_writes by exploiting lexical-only path checks in the permission gate. Attackers can commit symlinks pointing outside the workspace and use prompt injection to make the write tool write attacker-influenced content to external files without approval.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pulseaiclub phi 0.1.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in phi versions 0.1.1 through 0.28.4 due to improper link resolution. The permission gate uses lexical path checks without resolving symlinks, while underlying tools follow symlinks. Attackers can include symlinks in malicious repositories that bypass workspace restrictions, allowing unauthorized file reads or writes outside the intended workspace.

Detection Guidance

To detect this vulnerability, inspect phi installations for versions 0.1.1 through 0.28.4. Check for symlinks in repositories that point outside the workspace. Review file write operations for unexpected external writes or prompt injection attempts. Use commands like 'phi version' to verify version and 'find /path/to/workspace -type l' to locate symlinks.

Impact Analysis

An attacker could trick the system into reading sensitive files like SSH keys or writing malicious content to arbitrary system locations. This could lead to secret leakage, system compromise, or unauthorized file modifications without user approval.

Mitigation Strategies

Upgrade phi to a version beyond 0.28.4 where the symlink resolution issue is fixed. Disable headless runs without approval checks. Review and restrict workspace permissions. Monitor file write operations for suspicious paths. Apply patches from the phi repository addressing CWE-59.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108599. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart