Known Vulnerabilities for CodeWhale by Hmbown
Listed below are 10 of the newest known vulnerabilities associated with "CodeWhale" by "Hmbown".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-75915 json | CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails t... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75914 json | CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize ... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-75913 json | CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75912 json | CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to r... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-75911 json | CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files,... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75859 json | CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to ... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-75858 json | CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability ... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75857 json | CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whos... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-75856 json | CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to preven... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-45374 json | CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that... | Not Provided | 2026-05-28 | 2026-05-30 |