Hmbown / CodeWhale
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-75915 | CodeWhale before 0.8.64 Environment Variable Leak via js_execution | HIGH | 8.7 | Aug 18, 2026 |
| CVE-2026-75914 | CodeWhale before 0.8.64 Path Traversal via image_analyze symlink | HIGH | 8.7 | Aug 18, 2026 |
| CVE-2026-75913 | CodeWhale before 0.8.64 Argument Injection via git_show | HIGH | 8.5 | Aug 18, 2026 |
| CVE-2026-75912 | CodeWhale before 0.8.64 Argument Injection via git_blame | HIGH | 8.3 | Aug 18, 2026 |
| CVE-2026-75911 | CodeWhale before 0.8.64 Remote Code Execution via allow_shell | HIGH | 8.5 | Aug 18, 2026 |
| CVE-2026-75859 | CodeWhale before 0.8.64 Arbitrary File Read via instructions | HIGH | 8.7 | Aug 18, 2026 |
| CVE-2026-75858 | CodeWhale rlm_eval before 0.8.64 Remote Code Execution | HIGH | 8.5 | Aug 18, 2026 |
| CVE-2026-75857 | CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact | HIGH | 7.3 | Aug 18, 2026 |
| CVE-2026-75856 | CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU | CRITICAL | 9.2 | Aug 18, 2026 |
| CVE-2026-45311 | CodeWhale: run_tests Tool Enables RCE via Malicious Repository Without Approval | CRITICAL | 9.6 | May 28, 2026 |
| CVE-2026-45310 | CodeWhale: SSRF via HTTP Redirect Bypass in fetch_url Tool | HIGH | 7.4 | May 28, 2026 |
| CVE-2026-45373 | CodeWhale: SSRF IPV6 bypass | HIGH | 7.4 | May 28, 2026 |
| CVE-2026-45374 | CodeWhale: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files | CRITICAL | 9.6 | May 28, 2026 |
Showing 1 to 13 of 13 CVEs