VYPR
High severity7.5NVD Advisory· Published Aug 18, 2026· Updated Sep 8, 2026

CVE-2026-75914

CVE-2026-75914

Description

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to leak file bytes to the vision endpoint without user approval.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
deepseek-tuicrates.io
>= 0.8.32, <= 0.8.41—
deepseek-tuinpm
>= 0.8.32, < 0.8.410.8.41
codewhale-tuicrates.io
>= 0.8.41, < 0.8.640.8.64
codewhalenpm
>= 0.8.41, < 0.8.640.8.64

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.