SSRF Vulnerability in CodeWhale by Hmbown Affects DeepSeek + MiMo Agents
CVE-2026-45310

7.4HIGH

Key Information:

Vendor

Hmbown

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-45310?

CodeWhale, a coding agent that integrates DeepSeek and MiMo functionalities in terminal applications, contains a vulnerability that compromises internal services by allowing unauthorized requests. Specifically, prior to version 0.8.22, the fetch_url tool did not re-validate the final target of HTTP redirects against a restricted IP blocklist. This oversight can be exploited to carry out Server-Side Request Forgery (SSRF) attacks, potentially exposing sensitive internal network resources including cloud metadata endpoints and localhost services. Users are encouraged to upgrade to version 0.8.22 or later to mitigate these risks. For more details, please visit the official advisory and release notes provided by Hmbown.

Affected Version(s)

CodeWhale < 0.8.22

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.