CVE-2026-75859
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hmbown | CodeWhale | 0.8.8 < 0.8.41 | affected |
| Hmbown | CodeWhale | 0.8.41 | unaffected |
| Hmbown | CodeWhale | 0.8.8 < 0.8.41 | affected |
| Hmbown | CodeWhale | 0.8.41 | unaffected |
| Hmbown | CodeWhale | 0.8.41 < 0.8.64 | affected |
| Hmbown | CodeWhale | 0.8.64 | unaffected |
| Hmbown | CodeWhale | 0.8.41 < 0.8.64 | affected |
| Hmbown | CodeWhale | 0.8.64 | unaffected |
Weaknesses
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
References
- https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-62f5-cp2p-vq95
- https://github.com/Hmbown/CodeWhale/commit/43563356b98c6b993085554da82e77370160a31c
- https://www.vulncheck.com/advisories/codewhale-before-arbitrary-file-read-via-instructions
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.