CVE-2026-75914

Source
https://cve.org/CVERecord?id=CVE-2026-75914
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75914.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75914
Aliases
Published
2026-08-18T15:22:02Z
Modified
2026-09-10T03:30:58Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
CodeWhale before 0.8.64 Path Traversal via image_analyze symlink
Details

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to leak file bytes to the vision endpoint without user approval.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75914.json"
}
References

Affected packages

Git / github.com/hmbown/codewhale

Affected ranges

Type
GIT
Repo
https://github.com/hmbown/codewhale
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.8.32"
        },
        {
            "fixed": "0.8.41"
        },
        {
            "introduced": "0.8.41"
        },
        {
            "fixed": "0.8.64"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.8.32
v0.8.33
v0.8.35
v0.8.36
v0.8.37
v0.8.38
v0.8.39
v0.8.40
v0.8.41
v0.8.42
v0.8.43
v0.8.44
v0.8.45
v0.8.46
v0.8.48
v0.8.49
v0.8.50
v0.8.51
v0.8.52
v0.8.53
v0.8.54
v0.8.55
v0.8.56
v0.8.57
v0.8.58
v0.8.59
v0.8.60
v0.8.61
v0.8.62
v0.8.63

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75914.json"