PT-2026-77164 · Codewhale · Codewhale
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CodeWhale versions 0.8.41 through 0.8.63
Description
An argument injection issue exists in the
git show tool. The rev parameter is passed unvalidated into the git show argument vector without an --end-of-options sentinel, allowing a value starting with --output= to be interpreted as a git flag. Since the tool is auto-approved and considered read-only, an attacker using a malicious repository and prompt injection can perform an unprompted arbitrary file write with the privileges of the invoking user, potentially targeting files like ~/.ssh/authorized keys, ~/.bashrc, or ~/.gitconfig.Recommendations
Update CodeWhale to version 0.8.64.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Codewhale