---
id: CVE-2026-108600
title: >-
  open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link
  following vulnerability in the file_write tool sandbox that allows attackers
  to create files outside the workspace root by using dangling symlinks
summary: >-
  open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link
  following vulnerability in the file_write tool sandbox that allows attackers
  to create files outside the workspace root by using dangling symlinks.
  Attackers …
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-59
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T19:16:58.640'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108600'
references:
  - url: 'https://github.com/open-multi-agent/open-multi-agent'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/open-multi-agent/open-multi-agent/blob/6ec5498643c7e431aa66751f17f47a529e7f927c/packages/core/src/tool/built-in/file-write.ts#L67
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/open-multi-agent/open-multi-agent/blob/6ec5498643c7e431aa66751f17f47a529e7f927c/packages/core/src/tool/built-in/path-safety.ts#L104-L113
    label: disclosure@vulncheck.com
  - url: >-
      https://hackmd.io/@haind/open-multi-agent-file-write-dangling-symlink-escape
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/open-multi-agent-1.5.0-through-1.21.2-sandbox-escape-via-file-write-dangling-symlink
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-10T19:30:07.156Z'
---

## Overview

open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the file_write tool sandbox that allows attackers to create files outside the workspace root by using dangling symlinks. Attackers can plant a dangling symlink in the workspace and steer the agent via prompt injection to write attacker-influenced content anywhere the agent process can write.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
