CVE-2026-75859

Source
https://cve.org/CVERecord?id=CVE-2026-75859
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75859.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75859
Aliases
  • GHSA-62f5-cp2p-vq95
Published
2026-08-18T15:21:57.978Z
Modified
2026-08-21T03:30:13.998228224Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
CodeWhale before 0.8.64 Arbitrary File Read via instructions
Details

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75859.json"
}
References

Affected packages

Git / github.com/hmbown/codewhale

Affected ranges

Type
GIT
Repo
https://github.com/hmbown/codewhale
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.8.8"
        },
        {
            "fixed": "0.8.41"
        },
        {
            "introduced": "0.8.41"
        },
        {
            "fixed": "0.8.64"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.8.10
v0.8.11
v0.8.12
v0.8.13
v0.8.14
v0.8.15
v0.8.17
v0.8.18
v0.8.19
v0.8.20
v0.8.21
v0.8.22
v0.8.23
v0.8.24
v0.8.25
v0.8.26
v0.8.27
v0.8.28
v0.8.29
v0.8.30
v0.8.31
v0.8.32
v0.8.33
v0.8.35
v0.8.36
v0.8.37
v0.8.38
v0.8.39
v0.8.40
v0.8.41
v0.8.42
v0.8.43
v0.8.44
v0.8.45
v0.8.46
v0.8.48
v0.8.49
v0.8.50
v0.8.51
v0.8.52
v0.8.53
v0.8.54
v0.8.55
v0.8.56
v0.8.57
v0.8.58
v0.8.59
v0.8.60
v0.8.61
v0.8.62
v0.8.63
v0.8.8
v0.8.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75859.json"