{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-108595","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-10-10T18:08:12.414Z","datePublished":"2026-10-10T18:16:58.378Z","dateUpdated":"2026-10-10T18:16:58.378Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-10-10T18:16:58.378Z"},"datePublic":"2026-10-09T00:00:00.000Z","title":"Phi 0.3.0 through 0.28.4 Permission Bypass via agent_spawn Workdir","descriptions":[{"lang":"en","value":"Phi 0.3.0 through 0.28.4 contains a permission bypass vulnerability that allows spawned sub-agents to escape workspace_only_writes and readonly mode by supplying an unchecked workdir to agent_spawn. Attackers can plant prompt-injected instructions in processed content so the agent spawns a worker rooted elsewhere, causing unapproved file writes anywhere the user can write."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Incorrect Authorization","cweId":"CWE-863","type":"CWE"}]}],"affected":[{"vendor":"pulseaiclub","product":"phi","defaultStatus":"unaffected","versions":[{"version":"0.3.0","lessThanOrEqual":"0.28.4","status":"affected","versionType":"semver"}],"packageURL":"pkg:golang/github.com/pulseaiclub/phi","collectionURL":"https://pkg.go.dev","repo":"https://github.com/pulseaiclub/phi"}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":6,"baseSeverity":"MEDIUM"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}],"references":[{"url":"https://hackmd.io/@haind/phi-subagent-workdir-workspace-escape","tags":["third-party-advisory"]},{"url":"https://github.com/pulseaiclub/phi/blob/5b3cb440a7c58115ef64283a737a43299f2805a4/internal/tools/agenttool/agent.go#L106-L120","tags":["technical-description"]},{"url":"https://github.com/pulseaiclub/phi/blob/5b3cb440a7c58115ef64283a737a43299f2805a4/internal/agent/engine_runner.go#L52-L60","tags":["technical-description"]},{"url":"https://github.com/pulseaiclub/phi","tags":["product"]},{"name":"VulnCheck Advisory: Phi 0.3.0 through 0.28.4 Permission Bypass via agent_spawn Workdir","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/phi-0.3.0-through-0.28.4-permission-bypass-via-agent-spawn-workdir"}],"credits":[{"lang":"en","value":"HaiND from the Post and Telecommunication Institute of Technology","type":"finder"}],"x_generator":{"engine":"vulncheck-endgame"}}}}