Improper Link Resolution Vulnerability in phi by PulseAI Club
CVE-2026-108599

5.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-108599?

The phi product versions 0.1.1 to 0.28.4 exhibit an improper link resolution vulnerability that could allow malicious repositories to circumvent the workspace_only_writes restriction. This exploit takes advantage of lexical-only path checks within the permission gate, allowing attackers to create symlinks that point outside the designated workspace. Such actions can lead to unauthorized writing of attacker-controlled content to external files, thereby compromising system integrity and potentially manipulating sensitive data without user consent.

Affected Version(s)

phi 0.1.1 <= 0.28.4

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.