Permission Bypass in Phi by Pulse AI Club
CVE-2026-108595
6MEDIUM
What is CVE-2026-108595?
Versions of Phi from 0.3.0 to 0.28.4 are susceptible to a permission bypass vulnerability that enables sub-agents to exploit unchecked work directory inputs via the agent_spawn function. This flaw can lead attackers to execute prompt-injected instructions, allowing for file writes in locations where the user typically has write access. By circumventing the established workspace-only write and read-only modes, malicious users could potentially manipulate files outside the intended workspace, posing significant security risks.
Affected Version(s)
phi 0.3.0 <= 0.28.4
References
CVSS V4
Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
