deepseek-tui
Activity
- Latest release
- 1mo ago
- Total releases
- 73
- Cadence
- ~daily
- Last 12 months
- 73
Details
- License
- MIT
- First release
- Jan 19, 2026
| Version | Released | |
|---|---|---|
0.8.41
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.41
unknown
Dependencies (59)
+ 51 more |
|
0.8.40
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.40
unknown
Dependencies (59)
+ 51 more |
|
0.8.39
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.39
unknown
Dependencies (57)
+ 49 more |
|
0.8.38
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.38
unknown
Dependencies (57)
+ 49 more |
|
0.8.37
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.37
unknown
Dependencies (57)
+ 49 more |
|
0.8.36
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.36
unknown
Dependencies (57)
+ 49 more |
|
0.8.35
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.35
unknown
Dependencies (57)
+ 49 more |
|
0.8.34
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.34
unknown
Dependencies (57)
+ 49 more |
|
0.8.33
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75858
GHSA-wrj3-vj8c-784f
Sep 04, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryThe Details
The trait default at The engine's approval gate (
When PoCSource-level reproduction. Point a provider's
Run it through the non-interactive path ( ImpactUnsandboxed code execution on the user's workstation at the user's UID: read SSH keys, cloud credentials, CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.33
unknown
Dependencies (57)
+ 49 more |
|
0.8.32
unknown
8 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.32
unknown
Dependencies (57)
+ 49 more |
|
0.8.31
unknown
6 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.31
unknown
Dependencies (57)
+ 49 more |
|
0.8.30
unknown
6 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.30
unknown
Dependencies (57)
+ 49 more |
|
0.8.29
unknown
6 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.29
unknown
Dependencies (57)
+ 49 more |
|
0.8.28
unknown
6 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.28
unknown
Dependencies (55)
+ 47 more |
|
0.8.27
unknown
6 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.27
unknown
Dependencies (55)
+ 47 more |
|
0.8.26
unknown
6 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.26
unknown
Dependencies (55)
+ 47 more |
|
0.8.25
unknown
8 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.25
unknown
Dependencies (55)
+ 47 more |
|
0.8.24
unknown
8 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.24
unknown
Dependencies (55)
+ 47 more |
|
0.8.23
unknown
8 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.23
unknown
Dependencies (55)
+ 47 more |
|
0.8.22
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.22
unknown
Dependencies (55)
+ 47 more |
|
0.8.21
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.21
unknown
Dependencies (55)
+ 47 more |
|
0.8.20
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.20
unknown
Dependencies (55)
+ 47 more |
|
0.8.18
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.18
unknown
Dependencies (55)
+ 47 more |
|
0.8.17
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.17
unknown
Dependencies (55)
+ 47 more |
|
0.8.16
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.16
unknown
Dependencies (54)
+ 46 more |
|
0.8.15
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.15
unknown
Dependencies (54)
+ 46 more |
|
0.8.14
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.14
unknown
Dependencies (53)
+ 45 more |
|
0.8.13
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.13
unknown
Dependencies (53)
+ 45 more |
|
0.8.12
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.12
unknown
Dependencies (53)
+ 45 more |
|
0.8.11
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.11
unknown
Dependencies (53)
+ 45 more |
|
0.8.10
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.10
unknown
Dependencies (53)
+ 45 more |
|
0.8.9
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.9
unknown
Dependencies (53)
+ 45 more |
|
0.8.8
unknown
10 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.8
unknown
Dependencies (53)
+ 45 more |
|
0.8.7
unknown
9 CVEs
CVE-2026-75911
GHSA-gx45-xrj5-g6c4
Sep 04, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
Local
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. SummaryA malicious DetailsThe project config merge function at
No tightening guard exists for Source of attacker-controlled input: The Security boundary crossed: The Sink reached: Shell command execution via Why existing mitigations do not prevent exploitation:
Flow from source to sink:
PoCEnvironment: Any system with CodeWhale v0.8.50 built from source (commit Clean checkout recipe:
Cleanup:
ImpactThis is a high-severity privilege escalation / code execution vulnerability. Any user who clones a repository containing a malicious
Suggested remediation
CVE
Credits
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.7
unknown
Dependencies (53)
+ 45 more |
|
0.8.4
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.4
unknown
Dependencies (55)
+ 47 more |
|
0.8.3
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.3
unknown
Dependencies (55)
+ 47 more |
|
0.8.2
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.2
unknown
Dependencies (55)
+ 47 more |
|
0.8.1
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.1
unknown
Dependencies (55)
+ 47 more |
|
0.8.0
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.8.0
unknown
Dependencies (54)
+ 46 more |
|
0.7.4
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.7.4
unknown
Dependencies (54)
+ 46 more |
|
0.7.2
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.7.2
unknown
Dependencies (54)
+ 46 more |
|
0.7.1
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.7.1
unknown
Dependencies (54)
+ 46 more |
|
0.7.0
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.7.0
unknown
Dependencies (54)
+ 46 more |
|
0.6.5
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.6.5
unknown
Dependencies (49)
+ 41 more |
|
0.3.32
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.3.32
unknown
Dependencies (48)
+ 40 more |
|
0.3.27
unknown
7 CVEs
CVE-2026-75912
GHSA-c6mw-8xh8-gpq6
Sep 04, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
Network
Low
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Argument Injection in
|
0.3.27
unknown
Dependencies (48)
+ 40 more |
|
0.3.26
unknown
5 CVEs
CVE-2026-75857
GHSA-g29h-pfmp-qp9r
Sep 04, 2026
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
High
Local
High
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Summary
DetailsThe vulnerability requires two ordinary preconditions: shell tools are enabled (the normal config for using CodeWhale as a coding agent), and the session already has one approved long-running interactive process. After that, any untrusted content the agent reads can drive a
Same gate as the PoC
Driving the interactive TUI through a pty and scanning the output for an approval dialog shows the only When the approved process is privileged, the reach scales with it: ImpactCode or command execution inside an already-approved process, at that process's privilege level, with no prompt for the escalating input. Lower severity than the CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-45374
GHSA-72w5-pf8h-xfp4
May 14, 2026
DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
SummaryThe
When a user approves a PoCStep 1 — Create a malicious repo:
Step 2 — Open in DeepSeek-TUI:
Step 3 — Create a task:
The user sees an approval prompt for task creation — approve it. No Step 4 — Sub-agent executes attacker's payload: The sub-agent reads
ImpactA developer clones a malicious repository, opens it in DeepSeek-TUI, and asks for any task-based work (refactoring, documentation, bug fixing). The full attack chain:
The user approved one thing (task creation) but implicitly granted unrestricted shell access to a sub-agent that follows attacker-controlled instructions. This crosses the approval security boundary. Suggested Mitigation
Fixed in
0.8.26
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45373
GHSA-88gh-2526-gfrr
May 14, 2026
DeepSeek TUI has SSRF IPV6 bypass
7.4
/ 10
High
Network
Low
None
Required
Changed
High
None
None
SummaryAlthough SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in URL as Detailshttps://github.com/Hmbown/DeepSeek-TUI/blob/15f62e3e93d842f30b428877819ebc1c8cb96814/crates/tui/src/tools/fetch_url.rs#L321 PoCPrompt: ImpactAccess to local restricted resources Fixed in
0.8.26
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45311
GHSA-wx44-2q6h-j6p8
May 14, 2026
DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
SummaryThe
The attack is amplified by PoCStep 1 — Create a malicious Rust repo:
Step 2 — Open in DeepSeek-TUI:
Step 3 — Ask the model to run tests:
ImpactA malicious file in the repository (such as Suggested MitigationChange
Fixed in
0.8.23
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45310
GHSA-96ff-gc8g-wpvg
May 14, 2026
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
7.4
/ 10
High
Network
Low
None
Required
Changed
High
None
None
SummaryThe PoCStep 1 — Baseline: Confirm
Step 2 — SSRF bypass via redirect: Fetch a public URL that redirects to the restricted IP.
Expected result: The error message says "connection refused" or "request failed: connect error" — NOT "restricted address." This proves the SSRF filter was bypassed; the connection failed only because Observed result: Step 3 — Redirect to attacker-controlled host: Confirm attacker-controlled redirect targets are followed.
ImpactOn cloud-hosted instances (AWS, GCP, Azure), an attacker can exfiltrate cloud IAM credentials, instance metadata, and other sensitive internal service data by redirecting Fixed in
0.8.22
References
Updated Jun 09, 2026 · Source: OSV.dev |
0.3.26
unknown
Dependencies (48)
+ 40 more |
|
0.3.24
unknown
5 CVEs
CVE-2026-75857
GHSA-g29h-pfmp-qp9r
Sep 04, 2026
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
High
Local
High
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Summary
DetailsThe vulnerability requires two ordinary preconditions: shell tools are enabled (the normal config for using CodeWhale as a coding agent), and the session already has one approved long-running interactive process. After that, any untrusted content the agent reads can drive a
Same gate as the PoC
Driving the interactive TUI through a pty and scanning the output for an approval dialog shows the only When the approved process is privileged, the reach scales with it: ImpactCode or command execution inside an already-approved process, at that process's privilege level, with no prompt for the escalating input. Lower severity than the CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-45374
GHSA-72w5-pf8h-xfp4
May 14, 2026
DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
SummaryThe
When a user approves a PoCStep 1 — Create a malicious repo:
Step 2 — Open in DeepSeek-TUI:
Step 3 — Create a task:
The user sees an approval prompt for task creation — approve it. No Step 4 — Sub-agent executes attacker's payload: The sub-agent reads
ImpactA developer clones a malicious repository, opens it in DeepSeek-TUI, and asks for any task-based work (refactoring, documentation, bug fixing). The full attack chain:
The user approved one thing (task creation) but implicitly granted unrestricted shell access to a sub-agent that follows attacker-controlled instructions. This crosses the approval security boundary. Suggested Mitigation
Fixed in
0.8.26
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45373
GHSA-88gh-2526-gfrr
May 14, 2026
DeepSeek TUI has SSRF IPV6 bypass
7.4
/ 10
High
Network
Low
None
Required
Changed
High
None
None
SummaryAlthough SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in URL as Detailshttps://github.com/Hmbown/DeepSeek-TUI/blob/15f62e3e93d842f30b428877819ebc1c8cb96814/crates/tui/src/tools/fetch_url.rs#L321 PoCPrompt: ImpactAccess to local restricted resources Fixed in
0.8.26
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45311
GHSA-wx44-2q6h-j6p8
May 14, 2026
DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
SummaryThe
The attack is amplified by PoCStep 1 — Create a malicious Rust repo:
Step 2 — Open in DeepSeek-TUI:
Step 3 — Ask the model to run tests:
ImpactA malicious file in the repository (such as Suggested MitigationChange
Fixed in
0.8.23
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45310
GHSA-96ff-gc8g-wpvg
May 14, 2026
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
7.4
/ 10
High
Network
Low
None
Required
Changed
High
None
None
SummaryThe PoCStep 1 — Baseline: Confirm
Step 2 — SSRF bypass via redirect: Fetch a public URL that redirects to the restricted IP.
Expected result: The error message says "connection refused" or "request failed: connect error" — NOT "restricted address." This proves the SSRF filter was bypassed; the connection failed only because Observed result: Step 3 — Redirect to attacker-controlled host: Confirm attacker-controlled redirect targets are followed.
ImpactOn cloud-hosted instances (AWS, GCP, Azure), an attacker can exfiltrate cloud IAM credentials, instance metadata, and other sensitive internal service data by redirecting Fixed in
0.8.22
References
Updated Jun 09, 2026 · Source: OSV.dev |
0.3.24
unknown
Dependencies (47)
+ 39 more |
|
0.3.23
unknown
5 CVEs
CVE-2026-75857
GHSA-g29h-pfmp-qp9r
Sep 04, 2026
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
High
Local
High
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Summary
DetailsThe vulnerability requires two ordinary preconditions: shell tools are enabled (the normal config for using CodeWhale as a coding agent), and the session already has one approved long-running interactive process. After that, any untrusted content the agent reads can drive a
Same gate as the PoC
Driving the interactive TUI through a pty and scanning the output for an approval dialog shows the only When the approved process is privileged, the reach scales with it: ImpactCode or command execution inside an already-approved process, at that process's privilege level, with no prompt for the escalating input. Lower severity than the CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-45374
GHSA-72w5-pf8h-xfp4
May 14, 2026
DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
SummaryThe
When a user approves a PoCStep 1 — Create a malicious repo:
Step 2 — Open in DeepSeek-TUI:
Step 3 — Create a task:
The user sees an approval prompt for task creation — approve it. No Step 4 — Sub-agent executes attacker's payload: The sub-agent reads
ImpactA developer clones a malicious repository, opens it in DeepSeek-TUI, and asks for any task-based work (refactoring, documentation, bug fixing). The full attack chain:
The user approved one thing (task creation) but implicitly granted unrestricted shell access to a sub-agent that follows attacker-controlled instructions. This crosses the approval security boundary. Suggested Mitigation
Fixed in
0.8.26
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45373
GHSA-88gh-2526-gfrr
May 14, 2026
DeepSeek TUI has SSRF IPV6 bypass
7.4
/ 10
High
Network
Low
None
Required
Changed
High
None
None
SummaryAlthough SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in URL as Detailshttps://github.com/Hmbown/DeepSeek-TUI/blob/15f62e3e93d842f30b428877819ebc1c8cb96814/crates/tui/src/tools/fetch_url.rs#L321 PoCPrompt: ImpactAccess to local restricted resources Fixed in
0.8.26
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45311
GHSA-wx44-2q6h-j6p8
May 14, 2026
DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
SummaryThe
The attack is amplified by PoCStep 1 — Create a malicious Rust repo:
Step 2 — Open in DeepSeek-TUI:
Step 3 — Ask the model to run tests:
ImpactA malicious file in the repository (such as Suggested MitigationChange
Fixed in
0.8.23
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45310
GHSA-96ff-gc8g-wpvg
May 14, 2026
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
7.4
/ 10
High
Network
Low
None
Required
Changed
High
None
None
SummaryThe PoCStep 1 — Baseline: Confirm
Step 2 — SSRF bypass via redirect: Fetch a public URL that redirects to the restricted IP.
Expected result: The error message says "connection refused" or "request failed: connect error" — NOT "restricted address." This proves the SSRF filter was bypassed; the connection failed only because Observed result: Step 3 — Redirect to attacker-controlled host: Confirm attacker-controlled redirect targets are followed.
ImpactOn cloud-hosted instances (AWS, GCP, Azure), an attacker can exfiltrate cloud IAM credentials, instance metadata, and other sensitive internal service data by redirecting Fixed in
0.8.22
References
Updated Jun 09, 2026 · Source: OSV.dev |
0.3.23
unknown
Dependencies (47)
+ 39 more |
|
0.3.22
unknown
5 CVEs
CVE-2026-75857
GHSA-g29h-pfmp-qp9r
Sep 04, 2026
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
High
Local
High
None
Maintainer resolutionThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. Summary
DetailsThe vulnerability requires two ordinary preconditions: shell tools are enabled (the normal config for using CodeWhale as a coding agent), and the session already has one approved long-running interactive process. After that, any untrusted content the agent reads can drive a
Same gate as the PoC
Driving the interactive TUI through a pty and scanning the output for an approval dialog shows the only When the approved process is privileged, the reach scales with it: ImpactCode or command execution inside an already-approved process, at that process's privilege level, with no prompt for the escalating input. Lower severity than the CreditReferences
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-45374
GHSA-72w5-pf8h-xfp4
May 14, 2026
DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
SummaryThe
When a user approves a PoCStep 1 — Create a malicious repo:
Step 2 — Open in DeepSeek-TUI:
Step 3 — Create a task:
The user sees an approval prompt for task creation — approve it. No Step 4 — Sub-agent executes attacker's payload: The sub-agent reads
ImpactA developer clones a malicious repository, opens it in DeepSeek-TUI, and asks for any task-based work (refactoring, documentation, bug fixing). The full attack chain:
The user approved one thing (task creation) but implicitly granted unrestricted shell access to a sub-agent that follows attacker-controlled instructions. This crosses the approval security boundary. Suggested Mitigation
Fixed in
0.8.26
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45373
GHSA-88gh-2526-gfrr
May 14, 2026
DeepSeek TUI has SSRF IPV6 bypass
7.4
/ 10
High
Network
Low
None
Required
Changed
High
None
None
SummaryAlthough SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in URL as Detailshttps://github.com/Hmbown/DeepSeek-TUI/blob/15f62e3e93d842f30b428877819ebc1c8cb96814/crates/tui/src/tools/fetch_url.rs#L321 PoCPrompt: ImpactAccess to local restricted resources Fixed in
0.8.26
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45311
GHSA-wx44-2q6h-j6p8
May 14, 2026
DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
SummaryThe
The attack is amplified by PoCStep 1 — Create a malicious Rust repo:
Step 2 — Open in DeepSeek-TUI:
Step 3 — Ask the model to run tests:
ImpactA malicious file in the repository (such as Suggested MitigationChange
Fixed in
0.8.23
References
Updated Jun 09, 2026 · Source: OSV.dev
CVE-2026-45310
GHSA-96ff-gc8g-wpvg
May 14, 2026
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
7.4
/ 10
High
Network
Low
None
Required
Changed
High
None
None
SummaryThe PoCStep 1 — Baseline: Confirm
Step 2 — SSRF bypass via redirect: Fetch a public URL that redirects to the restricted IP.
Expected result: The error message says "connection refused" or "request failed: connect error" — NOT "restricted address." This proves the SSRF filter was bypassed; the connection failed only because Observed result: Step 3 — Redirect to attacker-controlled host: Confirm attacker-controlled redirect targets are followed.
ImpactOn cloud-hosted instances (AWS, GCP, Azure), an attacker can exfiltrate cloud IAM credentials, instance metadata, and other sensitive internal service data by redirecting Fixed in
0.8.22
References
Updated Jun 09, 2026 · Source: OSV.dev |
0.3.22
unknown
Dependencies (47)
+ 39 more |