Sceawere
Vulnerability Detail
CVE-2026-108595UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Phi Agent Workspace Sandbox Escape
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- pulseaiclub
- Product
- phi
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Phi 0.3.0 through 0.28.4 contains a permission bypass vulnerability that allows spawned sub-agents to escape workspace_only_writes and readonly mode by supplying an unchecked workdir to agent_spawn. Attackers can plant prompt-injected instructions in processed content so the agent spawns a worker rooted elsewhere, causing unapproved file writes anywhere the user can write.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-10T19:16:57.927Z",
"pubdate": "2026-10-10T19:16:57.927Z",
"executiveSummary": "Phi versions 0.3.0 through 0.28.4 contain a critical security vulnerability involving a sandbox escape within the agent spawning mechanism. The vulnerability resides in the insufficient validation of the workdir parameter passed to the agent_spawn function.\nThis flaw allows a malicious actor to bypass intended workspace_only_writes and readonly mode restrictions. By injecting instructions into processed content, an attacker can manipulate the sub-agent spawning process to define an arbitrary filesystem path as the working directory.\nThe vulnerability grants an attacker the capability to escape the restricted containerized or constrained environment of the primary agent. Consequently, the spawned sub-agent gains the ability to execute unauthorized file write operations on any directory accessible to the user context running the Phi application.\nThis constitutes a significant privilege escalation and integrity risk, as the attacker effectively bypasses established security policies governing agent operations. Successful exploitation requires the ability to influence the input processed by an agent, such as through prompt injection, making it a high-risk concern for systems integrating Phi with untrusted data sources.",
"technicalDetails": "The root cause of this vulnerability is improper input validation within the agent_spawn function in Phi versions 0.3.0 through 0.28.4. Specifically, the function fails to enforce constraints on the workdir argument, which determines the root directory for the spawned sub-agent.\nUnder normal operating conditions, the agent system enforces workspace_only_writes and readonly mode to ensure that agents operate strictly within designated, sandboxed directory structures. However, because the agent_spawn function accepts a user- or input-provided workdir without sanitizing or verifying the path against a whitelist of permitted directories, the sandbox can be bypassed.\nThe attack flow begins when an attacker performs a prompt injection on content processed by a Phi agent. The injected instructions are designed to manipulate the agent's logic to call the agent_spawn function with a maliciously crafted workdir parameter, such as an absolute system path or a path outside the intended workspace (e.g., '/etc' or user configuration directories).\nOnce the agent_spawn function is invoked with the attacker-controlled workdir, the resulting sub-agent inherits the privileges of the main agent process but is initialized with the requested, unrestricted working directory. Because the system checks intended for the sandbox were predicated on the assumption that the agent would remain confined to its assigned workspace, the sub-agent is able to bypass the file write restrictions.\nThe sub-agent, now operating in the attacker-specified directory, can perform arbitrary file writes. This allows for the modification, creation, or overwriting of sensitive system files, configuration files, or other user data that the parent process has permissions to access. The impact is a complete breach of the integrity of the filesystem from the perspective of the application, as the agent can deviate from its intended scope and potentially gain persistence or escalate privileges by overwriting system binaries or user-specific scripts.\nThis vulnerability does not require prior authentication to the agent's internal workings, as it is triggered via the processed content itself. The exploitation is restricted only by the filesystem permissions of the OS user running the Phi agent process; any location writable by that user becomes a target for the sub-agent's write operations."
}