Sceawere
Vulnerability Detail
CVE-2026-108759UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Arbitrary File Access via Symlinks
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 4h ago
- Vendor
- EricLBuehler
- Product
- mistral.rs
- Attack Type
- Improper Link Resolution Before File Access ('Link Following')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
mistral.rs 0.9.0 through 0.9.4 contains a link following vulnerability in mistralrs-code-exec that allows sandboxed shell code to read and overwrite files outside the sandbox via symlinks. Attackers or prompt-injected agents can name symlinks as outputs or reuse sessions with symlinked input paths to access files with the server process's permissions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-11T13:17:21.167Z",
"pubdate": "2026-10-11T13:17:21.167Z",
"executiveSummary": "The mistralrs-code-exec component in mistral.rs versions 0.9.0 through 0.9.4 is susceptible to a file-system traversal vulnerability stemming from improper validation of symbolic links within the sandboxed environment.\nThis vulnerability allows an attacker or a malicious prompt-injected agent to bypass sandbox constraints, facilitating unauthorized read and write access to files located outside the intended restricted directory.\nThe scope of impact is governed by the permissions of the underlying server process executing the mistral.rs instance, meaning the attacker inherits the system-level privileges of the host process.\nExploitation is achieved by creating symlinks that resolve to sensitive system files, which are then processed by the sandbox as legitimate input or output paths.\nThe risk is critical, as it compromises the integrity and confidentiality of the host environment, enabling potential data exfiltration or system modification via file overwriting.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient sanitization and path resolution logic within the mistralrs-code-exec sandboxing mechanism. When the sandbox handles file operations, it fails to verify that the target path remains strictly within the designated jail, allowing for the traversal of directory structures via symbolic links.\nIn versions 0.9.0 through 0.9.4, the code execution environment lacks a recursive check or a strict canonicalization strategy that would prevent symbolic links from escaping the sandboxed root. Attackers can leverage this by creating a symlink named as an output file or by manipulating the input path references during session reuse. Because the system calls resolve these symlinks before verifying permissions, the sandbox effectively treats the symlink as if it were a file located within the jail.\nThe attack flow proceeds as follows: First, the attacker initiates a sandboxed process or injects a prompt that triggers a code execution task. Second, the attacker defines an input or output path that is actually a symlink to a sensitive target (e.g., /etc/passwd or application configuration files). Third, when the mistralrs-code-exec engine performs a write or read operation on this defined path, the OS resolves the symlink, directing the I/O operation to the targeted file outside the sandbox.\nSince the sandbox environment executes with the identity of the host application, the application performs these I/O operations with the full permissions assigned to the service account. This allows for arbitrary read access to sensitive system data and the potential for destructive write operations if the application has write permissions to the targeted files. The exploitation does not require prior authentication to the underlying system, assuming the attacker has established a valid session context within the mistral.rs instance.\nThe impact is significant, as it nullifies the security boundary intended by the sandbox. An attacker could overwrite critical configuration files or binary paths to gain persistence, or exfiltrate sensitive secrets, tokens, or environment variables stored on the host machine. This vulnerability represents a failure in path-based security controls where symbolic link resolution precedes the security enforcement layer."
}