PT-2026-77166 · Codewhale · Codewhale
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CodeWhale versions prior to 0.8.64
Description
The
js execution tool fails to scrub parent process environment variables before spawning Node.js. This allows attackers to execute malicious JavaScript code that reads process.env to leak sensitive information, such as API keys, cloud credentials, and authentication tokens, back to the model context.Recommendations
Update CodeWhale to version 0.8.64 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Codewhale