Improper Link Resolution Vulnerability in phi by PulseAI Club
CVE-2026-108599
5.7MEDIUM
What is CVE-2026-108599?
The phi product versions 0.1.1 to 0.28.4 exhibit an improper link resolution vulnerability that could allow malicious repositories to circumvent the workspace_only_writes restriction. This exploit takes advantage of lexical-only path checks within the permission gate, allowing attackers to create symlinks that point outside the designated workspace. Such actions can lead to unauthorized writing of attacker-controlled content to external files, thereby compromising system integrity and potentially manipulating sensitive data without user consent.
Affected Version(s)
phi 0.1.1 <= 0.28.4
References
CVSS V4
Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
