GHSA-fjjm-5mgr-r8vpHighCVSS 6.8

mistral.rs 0.9.0 through 0.9.4 contains a link following vulnerability in mistralrs-code-exec...

Published
October 11, 2026
Last Modified
October 11, 2026

🔗 CVE IDs covered (1)

📋 Description

mistral.rs 0.9.0 through 0.9.4 contains a link following vulnerability in mistralrs-code-exec that allows sandboxed shell code to read and overwrite files outside the sandbox via symlinks. Attackers or prompt-injected agents can name symlinks as outputs or reuse sessions with symlinked input paths to access files with the server process's permissions.

🔗 References (7)