PatchSiren

open-multi-agent CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM open-multi-agent CVE published 2026-10-10

CVE-2026-108600

CVE-2026-108600 is a link following vulnerability in open-multi-agent (@open-multi-agent/core) versions 1.5.0 through 1.21.2. The vulnerability allows attackers to create files outside the workspace root by using dangling symlinks via the file_write tool sandbox. Attackers can plant a dangling symlink in the workspace and steer the agent via prompt injection to write attacker-influenced content anywhere t [truncated]