SSRF Vulnerability in CodeWhale by Hmbown Affects DeepSeek + MiMo Agents
CVE-2026-45310
7.4HIGH
What is CVE-2026-45310?
CodeWhale, a coding agent that integrates DeepSeek and MiMo functionalities in terminal applications, contains a vulnerability that compromises internal services by allowing unauthorized requests. Specifically, prior to version 0.8.22, the fetch_url tool did not re-validate the final target of HTTP redirects against a restricted IP blocklist. This oversight can be exploited to carry out Server-Side Request Forgery (SSRF) attacks, potentially exposing sensitive internal network resources including cloud metadata endpoints and localhost services. Users are encouraged to upgrade to version 0.8.22 or later to mitigate these risks. For more details, please visit the official advisory and release notes provided by Hmbown.
Affected Version(s)
CodeWhale < 0.8.22
