Back

HIGH

CodeWhale before 0.8.64 Remote Code Execution via allow_shell

Published Aug 18, 2026

Description

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a repository. When a user clones and opens the repository in CodeWhale, the AI model gains access to exec_shell and task_shell tools, enabling execution of arbitrary shell commands on the victim's machine without explicit user consent.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 18, 2026
Updated Aug 18, 2026
Reserved Aug 18, 2026
CISA Vulnrichment
Updated Aug 18, 2026
NVD
Status Deferred
Modified Sep 8, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-GX45-XRJ5-G6C4