PT-2026-77160 · Codewhale · Codewhale
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CodeWhale versions prior to 0.8.64
Description
Insufficient validation of file paths in the project config instructions field allows for the reading of arbitrary files on a system. An attacker can use a malicious
.codewhale/config.toml file within a cloned repository to specify paths outside the workspace. These files are then read and injected into the AI system prompt, which can be used for data exfiltration.Recommendations
Update to version 0.8.64 or later.
Exploit
Fix
Information Disclosure
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Codewhale