CVE-2026-108599 is a medium-severity vulnerability in phi versions 0.1.1 through 0.28.4. It allows malicious repositories to bypass workspace_only_writes by exploiting lexical-only path checks in the permission gate, potentially enabling attackers to commit symlinks pointing outside the workspace and write attacker-influenced content to external files without approval. Defenders should prioritize verifyin [truncated]
CVE-2026-108595 is a permission bypass vulnerability in Phi versions 0.3.0 through 0.28.4. Attackers can exploit this vulnerability to allow spawned sub-agents to escape workspace_only_writes and readonly mode, potentially leading to unapproved file writes. This vulnerability can be triggered by supplying an unchecked workdir to agent_spawn, which could lead to unapproved file writes anywhere the user can [truncated]