CVE-2026-75911
CodeWhale before 0.8.64 Remote Code Execution via allow_shell
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a repository. When a user clones and opens the repository in CodeWhale, the AI model gains access to exec_shell and task_shell tools, enabling execution of arbitrary shell commands on the victim's machine without explicit user consent.
| CWE | CWE-94 |
| Vendor | hmbown |
| Product | codewhale |
| Published | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for hmbown codewhale
Be the first to know when new high vulnerabilities affecting hmbown codewhale are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Hmbown / CodeWhale
0.8.6 < 0.8.41
Hmbown / CodeWhale
0.8.6 < 0.8.41
Hmbown / CodeWhale
0.8.41 < 0.8.64
Hmbown / CodeWhale
0.8.41 < 0.8.64
References
Credits
๐ sondt99 ๐ dungNHVhust