Skip to content
Symlink Traversal Flaw in brig Allows Sandbox Escape

Symlink Traversal Flaw in brig Allows Sandbox Escape

First seen 29 Sep 2026, 19:12 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 18:35 UTC
  • •A critical symlink traversal flaw in brig allows unauthorized host directory access.
  • •The vulnerability affects brig versions prior to 0.3.0 and has a CVSS score of 8.2.
  • •Sensitive files like SSH keys and cloud credentials can be exposed due to this flaw.

A critical flaw in the brig tool allows an AI agent to create a symlink that can access arbitrary host directories, leading to potential exposure of sensitive files like SSH keys and cloud credentials. This vulnerability, tracked as GHSA-wp6x-29qx-fpr7 and ENDOR-VUL-2026-1809, has a CVSS score of 8.2. The issue arises because brig passes the project path to the runtime without resolving it, enabling an agent to replace a subdirectory with a symlink pointing to any location on the host. The flaw affects users running brig versions prior to 0.3.0, which has since been patched. The vulnerability was confirmed on macOS 15 and Ubuntu 24.04 systems. The impact is significant, as it allows unauthorized access to sensitive files with the permissions of the user running brig. Users are urged to update to the latest version to mitigate this risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-29
Vulnerability disclosed
Endorlabs published details about the symlink traversal flaw in brig, highlighting its potential impact.
Endorlabs
2026-09-29
Advisory published
GitHub published an advisory detailing the symlink traversal vulnerability and its implications.
github.com
2026-09-29
Patch released
Brig version 0.3.0 was released to fix the symlink traversal vulnerability.
Endorlabs

More articles in this cluster (2)

Following this threat?

Track Endor Labs in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed