PT-2026-77160 · Codewhale · Codewhale

·

CVE-2026-75859

·

Published

2026-08-18

·

Updated

2026-09-04

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CodeWhale versions prior to 0.8.64
Description Insufficient validation of file paths in the project config instructions field allows for the reading of arbitrary files on a system. An attacker can use a malicious .codewhale/config.toml file within a cloned repository to specify paths outside the workspace. These files are then read and injected into the AI system prompt, which can be used for data exfiltration.
Recommendations Update to version 0.8.64 or later.

Exploit

Fix

Information Disclosure

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75859
GHSA-62F5-CP2P-VQ95

Affected Products

Codewhale