PT-2026-77159 · Codewhale · Codewhale
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CodeWhale versions 0.8.41 through 0.8.63
Description
A remote code execution issue exists in the
rlm eval tool. The approval requirement() function returns ApprovalRequirement::Auto, which the engine interprets as a command to never prompt the user. This allows arbitrary Python code supplied by a model to execute in a python3 interpreter, bypassing the configured --approval-policy and omitting any approval prompt or audit step. An attacker can trigger this by using prompt injection within untrusted content read by the agent, such as web pages, fetched URLs, repository files, or MCP tool results. The rlm open tool can be used to stage this content. The executed code runs on the local machine with the privileges of the user.Recommendations
Update to version 0.8.64.
Exploit
Fix
RCE
Missing Authorization
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Codewhale