CVE-2026-108600: open-multi-agent 1.5.0 through 1.21.2 Sandbox Escape via file_write Dangling Symlink
open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the filewrite tool sandbox that allows attackers to create files outside the workspace root by using dangling symlinks. Attackers can plant a dangling symlink in the workspace and steer the agent via prompt injection to write attacker-influenced content anywhere the agent process can write.
Affected Software
Event History
Frequently Asked Questions
Which deployments are realistically exposed?
Deployments using @open-multi-agent/core versions 1.5.0 through 1.21.2 are exposed when an attacker can place a dangling symlink in the workspace and influence the agent through prompt injection.
What does an attacker need to exploit this issue?
The attacker needs to plant a dangling symlink within the workspace and steer the agent to use the file_write tool on that path. Exploitation also depends on the agent process having write permission to the target location outside the workspace.
How can I assess whether my installation is affected?
Check whether the installed @open-multi-agent/core version is between 1.5.0 and 1.21.2. Also review workspaces for dangling symlinks and determine whether untrusted content can prompt the agent to perform file_write operations.