CodeWhale version 0.8.64 fixes multiple high-severity vulnerabilities affecting the codewhale and codewhale-tui packages, including remote code execution, SSRF bypass, path traversal, and argument injection bugs. The most severe issue, CVE-2026-75858, allowed model-supplied Python code in rlm_eval to run automatically without honoring user approval settings, enabling local code execution through prompt-injection content delivered via web pages, fetched URLs, repository files, or MCP tool results. Additional flaws included CVE-2026-75856, a DNS pinning TOCTOU weakness that could bypass SSRF protections and reach internal network resources, and CVE-2026-75914, which let attackers abuse symlinks in image_analyze to read files outside the workspace and leak their contents to the vision endpoint.
The release also addressed Git tool injection risks that could expose or modify local files. CVE-2026-75912 allowed attackers to pass crafted rev values to git_blame and read arbitrary files through injected Git options, while CVE-2026-75913 let malicious input reach git_show without proper validation or an end-of-options guard, enabling arbitrary file writes to targets such as ~/.ssh/authorized_keys or shell configuration files. A related hardening commit shows CodeWhale tightened local tool trust boundaries by resolving hosts before fetch_url requests, sanitizing the child environment for JavaScript execution so parent secrets are not inherited, and canonicalizing image paths to block symlink escapes from the workspace.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
On August 18, 2026, CVE-2026-75914 was published for a path traversal vulnerability in CodeWhale's image_analyze tool affecting versions before 0.8.64. The flaw let attackers use workspace symlinks to external files to leak file bytes to the vision endpoint, and the remediation was to upgrade to 0.8.64 or later.
On August 18, 2026, CVE-2026-75913 was published for an argument injection vulnerability in CodeWhale's git_show tool affecting versions 0.8.41 through 0.8.63. The flaw allowed attacker-controlled rev values to be interpreted as Git flags and could enable arbitrary file writes; version 0.8.64 fixed the issue.
On August 18, 2026, CVE-2026-75912 was published for an argument injection flaw in CodeWhale's git_blame tool affecting versions before 0.8.64. The issue allowed attacker-controlled rev values such as --contents=/path/to/file to read arbitrary files through tool output, with 0.8.64 listed as the fixed version.
On August 18, 2026, CVE-2026-75858 was published for a remote code execution issue in CodeWhale's rlm_eval tool affecting versions 0.8.41 through 0.8.63. The flaw let model-supplied Python execute without honoring the user's approval policy, and version 0.8.64 was identified as the fix.
On August 18, 2026, CVE-2026-75856 was published for a DNS pinning TOCTOU flaw in CodeWhale before 0.8.64 that could let remote attackers bypass SSRF protections and reach internal IP addresses. The advisory identified version 0.8.64 as the fix and referenced commit 26de44a.
On June 21, 2026, Hmbown committed change 4356335 to the CodeWhale repository to stop project-local TUI configuration from loosening security policy. The change prevents project config from enabling shell access or replacing user-owned instruction file lists, while still allowing project config to disable shell access and emitting warnings for ignored settings.
On June 21, 2026, Hmbown committed change 26de44a to the CodeWhale repository. The commit added hostname preflight checks for fetch_url, sanitized the child environment for js_execution, and enforced canonicalized workspace-bound path validation for image_analyze, with tests covering each change.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
9 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.