Sceawere
Vulnerability Detail
CVE-2026-108599UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Phi Path Traversal via Symlinks
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 3h ago
- Vendor
- pulseaiclub
- Product
- phi
- Attack Type
- Improper Link Resolution Before File Access ('Link Following')
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
phi 0.1.1 through 0.28.4 contains an improper link resolution vulnerability that allows malicious repositories to bypass workspace_only_writes by exploiting lexical-only path checks in the permission gate. Attackers can commit symlinks pointing outside the workspace and use prompt injection to make the write tool write attacker-influenced content to external files without approval.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-10-10T19:16:58.487Z",
"pubdate": "2026-10-10T19:16:58.487Z",
"executiveSummary": "The phi software library, specifically versions 0.1.1 through 0.28.4, contains a critical improper link resolution vulnerability. This flaw allows malicious repositories to bypass the workspace_only_writes security constraint, which is intended to restrict file system operations to a defined directory.\nThe vulnerability originates from a flawed permission gate that relies solely on lexical path checks rather than verifying the resolved canonical path. By committing symlinks that resolve to locations outside the designated workspace, an attacker can manipulate the system's write operations.\nThis vulnerability is exacerbated by potential integration with prompt injection vectors. An attacker can leverage prompt injection to force the application's write tool to interact with these malicious symlinks, ultimately resulting in unauthorized writes to arbitrary files on the host system. The impact is significant, as it grants attackers the capability to perform unauthorized file system modifications beyond the intended scope, potentially leading to remote code execution, sensitive data corruption, or system configuration compromise.\nExploitation requires the victim to use a malicious repository in conjunction with the vulnerable phi library. No specific authentication is required if the victim executes the application against an attacker-controlled workspace.",
"technicalDetails": "The root cause of this vulnerability is an inadequate implementation of path validation within the phi library's permission gate. The system employs lexical-only path checks to enforce the workspace_only_writes security policy. This method fails to account for symbolic links (symlinks), as it merely evaluates the path string rather than resolving the path to its absolute, canonical form on the underlying file system.\nIn versions 0.1.1 through 0.28.4, the validation logic permits paths that appear syntactically compliant with workspace restrictions. However, an attacker can craft a malicious repository containing a symlink that points to a target outside the workspace directory. When the write tool processes this symlink, the operating system resolves the path to the intended external destination, effectively bypassing the security check.\nThe attack flow follows a structured sequence: 1) The attacker commits a symlink to a repository that, when resolved, traverses outside the established workspace boundary. 2) The victim utilizes the affected phi library to interact with this repository. 3) The attacker utilizes a prompt injection attack to command the application's write tool to perform a write operation targeting the malicious symlink path. 4) The permission gate, performing only a lexical check on the symlink path string, validates the request as being within the workspace. 5) The application executes the write operation, which the OS resolves to the external file location. 6) The content provided via the prompt injection payload is subsequently written to the unauthorized external file.\nThis mechanism allows for arbitrary file writes, constrained only by the privileges of the process executing the phi library. If the library is running with elevated permissions, the impact is severe. Post-exploitation activities could involve overwriting configuration files, injecting malicious scripts into startup folders, or modifying sensitive system binaries to achieve persistent command execution or local privilege escalation."
}