Description
mistral.rs 0.9.0 through 0.9.4 contains a link following vulnerability in mistralrs-code-exec that allows sandboxed shell code to read and overwrite files outside the sandbox via symlinks. Attackers or prompt-injected agents can name symlinks as outputs or reuse sessions with symlinked input paths to access files with the server process's permissions.
Published: 2026-10-11
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Sandbox Escape via Symlink Following
Action: Upgrade
AI Analysis

Impact

mistral.rs versions 0.9.0 through 0.9.4 contain a link‑following flaw that lets sandboxed shell code access files outside the intended sandbox, including reading or overwriting arbitrary files with the permissions of the server process. The vulnerability allows an attacker, or a prompt‑injected agent, to name a symlink as an output path or reuse a session with symlinked input paths, thereby striking at sensitive system files, configuration data, or executables. This compromise could compromise the confidentiality and integrity of the system and may serve as a foothold for more advanced attacks. Based on the description, it is inferred that the impact is to liberate privileged file access to sandboxed operations.

Affected Systems

The affected product is mistral.rs by EricLBuehler. All releases from version 0.9.0 to and including 0.9.4 are vulnerable. No additional affected versions are listed.

Risk and Exploitability

The CVSS base score is 7.6, indicating a high severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through sandboxed code execution or prompt‑injected agents that can specify output or input paths containing symlinks. Exploitation requires the attacker to be able to influence the path names used by mistralrs-code-exec; once achieved, the attacker can read or overwrite files with the server’s process permissions.

Generated by OpenCVE AI on October 11, 2026 at 13:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to mistral.rs 0.9.5 or newer where the symlink following issue is fixed.
  • If an upgrade is not feasible, configure the execution environment to disallow symlink creation or resolve all symlinks before passing paths to code execution.
  • Validate and sanitize all output or input paths in the application code, rejecting or normalizing any paths that resolve to symlinks outside the intended sandbox.

Generated by OpenCVE AI on October 11, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Ericlbuehler
Ericlbuehler mistral.rs
Vendors & Products Ericlbuehler
Ericlbuehler mistral.rs

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description mistral.rs 0.9.0 through 0.9.4 contains a link following vulnerability in mistralrs-code-exec that allows sandboxed shell code to read and overwrite files outside the sandbox via symlinks. Attackers or prompt-injected agents can name symlinks as outputs or reuse sessions with symlinked input paths to access files with the server process's permissions.
Title mistral.rs 0.9.0 through 0.9.4 Sandbox Escape via Symlink Following in mistralrs-code-exec
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ericlbuehler Mistral.rs
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:56.496Z

Reserved: 2026-10-11T01:57:28.334Z

Link: CVE-2026-108759

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:21.167

Modified: 2026-10-11T13:17:21.167

Link: CVE-2026-108759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:00:18Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')