VYPR

CodeWhale

by Hmbown

CVEs (4)

  • CVE-2026-75856HigAug 18, 2026
    risk 0.49cvss 8.6epss

    CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing…

  • CVE-2026-75911HigAug 18, 2026
    risk 0.44cvss 7.8epss

    CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a repository. When a user clones…

  • CVE-2026-75912HigAug 18, 2026
    risk 0.41cvss 7.4epss

    CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values like --contents=/path/to/file to…

  • CVE-2026-75857HigAug 18, 2026
    risk 0.38cvss 7.0epss

    CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-executing tools, so LLM-controlled stdin…