Impact
mistral.rs versions 0.9.0 through 0.9.4 contain a link‑following flaw that lets sandboxed shell code access files outside the intended sandbox, including reading or overwriting arbitrary files with the permissions of the server process. The vulnerability allows an attacker, or a prompt‑injected agent, to name a symlink as an output path or reuse a session with symlinked input paths, thereby striking at sensitive system files, configuration data, or executables. This compromise could compromise the confidentiality and integrity of the system and may serve as a foothold for more advanced attacks. Based on the description, it is inferred that the impact is to liberate privileged file access to sandboxed operations.
Affected Systems
The affected product is mistral.rs by EricLBuehler. All releases from version 0.9.0 to and including 0.9.4 are vulnerable. No additional affected versions are listed.
Risk and Exploitability
The CVSS base score is 7.6, indicating a high severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through sandboxed code execution or prompt‑injected agents that can specify output or input paths containing symlinks. Exploitation requires the attacker to be able to influence the path names used by mistralrs-code-exec; once achieved, the attacker can read or overwrite files with the server’s process permissions.
OpenCVE Enrichment