Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 10 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Phi 0.3.0 through 0.28.4 contains a permission bypass vulnerability that allows spawned sub-agents to escape workspace_only_writes and readonly mode by supplying an unchecked workdir to agent_spawn. Attackers can plant prompt-injected instructions in processed content so the agent spawns a worker rooted elsewhere, causing unapproved file writes anywhere the user can write. | |
| Title | Phi 0.3.0 through 0.28.4 Permission Bypass via agent_spawn Workdir | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T18:16:58.378Z
Reserved: 2026-10-10T18:08:12.414Z
Link: CVE-2026-108595
No data.
Status : Received
Published: 2026-10-10T19:16:57.927
Modified: 2026-10-10T19:16:57.927
Link: CVE-2026-108595
No data.
OpenCVE Enrichment
Updated: 2026-10-10T20:00:13Z
-
CWE-863
Incorrect Authorization