High severity7.5NVD Advisory· Published Aug 18, 2026
CVE-2026-75859
CVE-2026-75859
Description
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.