codewhale-tui
Open-source coding agent for your terminal, built in Rust and on a journey of continuous community improvement. Issues and PRs welcome.
Activity
- Latest release
- 4h ago
- Total releases
- 39
- Cadence
- ~daily
- Last 12 months
- 39
Reach
- Downloads
- 8.8k
- Stars
- 41.0k
Details
- License
- MIT
- First release
- May 23, 2026
| Version | Released | |
|---|---|---|
0.9.13
patch
|
0.9.13
patch
Dependencies (98)
+ 90 more
Changelog
Compare changes
|
|
0.9.12
patch
|
0.9.12
patch
Dependencies (90)
+ 82 more
Changelog
Compare changes
|
|
0.9.11
patch
|
0.9.11
patch
Dependencies (90)
+ 82 more
Changelog
Compare changes
|
|
0.9.10
patch
|
0.9.10
patch
Dependencies (90)
+ 82 more
Changelog
Compare changes
|
|
0.9.9
patch
|
0.9.9
patch
Dependencies (89)
+ 81 more
Changelog
Compare changes
|
|
0.9.8
patch
|
0.9.8
patch
Dependencies (89)
+ 81 more
Changelog
Compare changes
|
|
0.9.7
patch
|
0.9.7
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
0.9.6
patch
|
0.9.6
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
0.9.5
patch
|
0.9.5
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
0.9.4
patch
|
0.9.4
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
0.9.3
patch
|
0.9.3
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
0.9.2
patch
|
0.9.2
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
0.9.1
patch
|
0.9.1
patch
Dependencies (85)
+ 77 more
Changelog
Compare changes
|
|
0.9.0
minor
|
0.9.0
minor
Dependencies (79)
+ 71 more
Changelog
Compare changes
|
|
0.8.67
patch
|
0.8.67
patch
Dependencies (75)
+ 67 more
Changelog
Compare changes
|
|
0.8.66
patch
|
0.8.66
patch
Dependencies (71)
+ 63 more
Changelog
Compare changes
|
|
0.8.65
patch
|
0.8.65
patch
Dependencies (69)
+ 61 more
Changelog
Compare changes
|
|
0.8.64
patch
|
0.8.64
patch
Dependencies (65)
+ 57 more
Changelog
Compare changes
|
|
0.8.63
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.63
patch
Dependencies (65)
+ 57 more
Changelog
Compare changes
|
|
0.8.62
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.62
patch
Dependencies (65)
+ 57 more
Changelog
Compare changes
|
|
0.8.61
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.61
patch
Dependencies (64)
+ 56 more
Changelog
Compare changes
|
|
0.8.60
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.60
patch
Dependencies (64)
+ 56 more
Changelog
Compare changes
|
|
0.8.59
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.59
patch
Dependencies (64)
+ 56 more
Changelog
Compare changes
|
|
0.8.58
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.58
patch
Dependencies (64)
+ 56 more
Changelog
Compare changes
|
|
0.8.57
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.57
patch
Dependencies (64)
+ 56 more
Changelog
Compare changes
|
|
0.8.56
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.56
patch
Dependencies (66)
+ 58 more
Changelog
Compare changes
|
|
0.8.54
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.54
patch
Dependencies (66)
+ 58 more
Changelog
Compare changes
|
|
0.8.53
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.53
patch
Dependencies (63)
+ 55 more
Changelog
Compare changes
|
|
0.8.52
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.52
patch
Dependencies (63)
+ 55 more
Changelog
Compare changes
|
|
0.8.50
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.50
patch
Dependencies (63)
+ 55 more
Changelog
Compare changes
|
|
0.8.49
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.49
patch
Dependencies (63)
+ 55 more
Changelog
Compare changes
|
|
0.8.48
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.48
patch
Dependencies (63)
+ 55 more
Changelog
Compare changes
|
|
0.8.47
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.47
patch
Dependencies (60)
+ 52 more
Changelog
Compare changes
|
|
0.8.46
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.46
patch
Dependencies (60)
+ 52 more
Changelog
Compare changes
|
|
0.8.45
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.45
patch
Dependencies (60)
+ 52 more
Changelog
Compare changes
|
|
0.8.44
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.44
patch
Dependencies (60)
+ 52 more
Changelog
Compare changes
|
|
0.8.43
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.43
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
0.8.42
patch
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.42
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
0.8.41
initial
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
Fixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditFixed in
0.8.64
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.41
initial
Dependencies (59)
+ 51 more
Changelog
|