CVE-2026-108751
Received Received - Intake

Improper Link Resolution in MoAI-ADK via Symlinked .moai-tmp

Vulnerability report for CVE-2026-108751, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

MoAI-ADK through 3.1.2 contains an improper link resolution vulnerability in the moai init template deployer that allows malicious repositories to overwrite files outside the project via a symlinked .moai-tmp staging path. Attackers can commit a symlink such as .claude/settings.json.moai-tmp so atomicWriteFile truncates and overwrites victim-writable files with MoAI template content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
modu-ai moai-adk 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MoAI-ADK through version 3.1.2 has an improper link resolution flaw in its moai init template deployer. This allows attackers to exploit symlinks to overwrite files outside the project directory. For example, a malicious repository could include a symlink like .claude/settings.json.moai-tmp, which causes the system to overwrite victim-writable files with MoAI template content during deployment.

Detection Guidance

Check for suspicious symlinks in .moai-tmp directories or project files. Inspect file writes to sensitive locations like .claude/settings.json. Review git history for unexpected file modifications or symlink commits.

Impact Analysis

If you use MoAI-ADK, an attacker could overwrite critical files on your system by tricking you into using a malicious repository. This could corrupt configuration files, settings, or other sensitive data. The impact is limited to files you have write permissions for, but it could disrupt applications or expose data depending on which files are overwritten.

Compliance Impact

This vulnerability could lead to unauthorized file modifications, potentially violating integrity requirements in GDPR or HIPAA. If sensitive data files are overwritten, it may result in data corruption or exposure, which could breach compliance obligations for data protection and integrity.

Mitigation Strategies

Update MoAI-ADK to a patched version. Restrict write permissions to sensitive directories. Audit and remove any .moai-tmp staging paths. Monitor for unauthorized file modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108751. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart