CVE-2026-75859 PUBLISHED

CodeWhale before 0.8.64 Arbitrary File Read via instructions

Assigner: VulnCheck
Reserved: 18.08.2026 Published: 18.08.2026 Updated: 18.08.2026

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Hmbown
Product CodeWhale
Versions Default: unaffected
  • affected from 0.8.8 to 0.8.41 (excl.)
  • Version 0.8.41 is unaffected
Vendor Hmbown
Product CodeWhale
Versions Default: unaffected
  • affected from 0.8.8 to 0.8.41 (excl.)
  • Version 0.8.41 is unaffected
Vendor Hmbown
Product CodeWhale
Versions Default: unaffected
  • affected from 0.8.41 to 0.8.64 (excl.)
  • Version 0.8.64 is unaffected
Vendor Hmbown
Product CodeWhale
Versions Default: unaffected
  • affected from 0.8.41 to 0.8.64 (excl.)
  • Version 0.8.64 is unaffected

Credits

  • sondt99 reporter
  • dungNHVhust reporter
  • sai-sh reporter

References

Problem Types

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE