PT-2026-77165 · Codewhale · Codewhale

·

CVE-2026-75914

·

Published

2026-08-18

·

Updated

2026-09-04

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CodeWhale versions prior to 0.8.64
Description The image analyze tool fails to canonicalize symlinks before reading files, leading to a path traversal issue. This allows attackers to create workspace symlinks that point to external files with image extensions, enabling the leakage of file bytes to the vision endpoint without user approval. Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder.
Recommendations Update to version 0.8.64 or later.

Exploit

Fix

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75914
GHSA-W7WX-5Q49-R59W

Affected Products

Codewhale