Code Execution Vulnerability in CodeWhale by Hmbown
CVE-2026-45311

9.6CRITICAL

Key Information:

Vendor

Hmbown

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-45311?

The CodeWhale product from Hmbown has a vulnerability where the run_tests tool can execute cargo test commands without user approval. This behavior, intended for automated testing, poses security risks as it allows the execution of arbitrary code, including malicious shell commands, in a compromised repository. Attackers can leverage this flaw to exfiltrate sensitive information or maintain persistence on the system, compounding the threat as the automated execution can occur at session start without user intervention. The issue has been addressed in version 0.8.23.

Affected Version(s)

CodeWhale >= 0.3.0, < 0.8.23

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.