CVE-2026-108595: Phi 0.3.0 through 0.28.4 Permission Bypass via agent_spawn Workdir
Phi 0.3.0 through 0.28.4 contains a permission bypass vulnerability that allows spawned sub-agents to escape workspaceonlywrites and readonly mode by supplying an unchecked workdir to agentspawn. Attackers can plant prompt-injected instructions in processed content so the agent spawns a worker rooted elsewhere, causing unapproved file writes anywhere the user can write.
Affected Software
Event History
Frequently Asked Questions
Does this issue expose data or disrupt service availability?
The reported impact is limited to integrity: it enables unapproved file writes. No confidentiality or availability impact is indicated by the supplied CVSS vector.
What access level can an attacker gain through the bypass?
The attacker can cause writes anywhere that the user running Phi is permitted to write. The issue does not grant permissions beyond that user's existing filesystem access.
What conditions are needed for exploitation?
Exploitation requires processed content containing prompt-injected instructions that cause the agent to spawn a sub-agent with an attacker-controlled workdir. User interaction is also required according to the supplied CVSS vector.