CVE-2026-108595 | pulseaiclub Phi up to 0.28.4 Sub-agent Spawning agent_spawn workdir permission
A vulnerability was found in pulseaiclub Phi up to 0.28.4. It has been rated as problematic. This issue affects the function agent_spawn of the component Sub-agent Spawning. The manipulation of the argument workdir leads to permission issues.
This vulnerability is referenced as CVE-2026-108595. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More