CVE-2026-75911

Source
https://cve.org/CVERecord?id=CVE-2026-75911
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75911.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75911
Aliases
Published
2026-08-18T15:21:59Z
Modified
2026-09-10T03:31:01Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
CodeWhale before 0.8.64 Remote Code Execution via allow_shell
Details

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a repository. When a user clones and opens the repository in CodeWhale, the AI model gains access to exec_shell and task_shell tools, enabling execution of arbitrary shell commands on the victim's machine without explicit user consent.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75911.json"
}
References

Affected packages

Git / github.com/hmbown/codewhale

Affected ranges

Type
GIT
Repo
https://github.com/hmbown/codewhale
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.8.6"
        },
        {
            "fixed": "0.8.41"
        },
        {
            "introduced": "0.8.41"
        },
        {
            "fixed": "0.8.64"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.8.10
v0.8.11
v0.8.12
v0.8.13
v0.8.14
v0.8.15
v0.8.17
v0.8.18
v0.8.19
v0.8.20
v0.8.21
v0.8.22
v0.8.23
v0.8.24
v0.8.25
v0.8.26
v0.8.27
v0.8.28
v0.8.29
v0.8.30
v0.8.31
v0.8.32
v0.8.33
v0.8.35
v0.8.36
v0.8.37
v0.8.38
v0.8.39
v0.8.40
v0.8.41
v0.8.42
v0.8.43
v0.8.44
v0.8.45
v0.8.46
v0.8.48
v0.8.49
v0.8.50
v0.8.51
v0.8.52
v0.8.53
v0.8.54
v0.8.55
v0.8.56
v0.8.57
v0.8.58
v0.8.59
v0.8.6
v0.8.60
v0.8.61
v0.8.62
v0.8.63
v0.8.7
v0.8.8
v0.8.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75911.json"