SSRF Vulnerability in CodeWhale from Hmbown
CVE-2026-45373

7.4HIGH

Key Information:

Vendor

Hmbown

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-45373?

CodeWhale, a coding agent that integrates DeepSeek and MiMo functionalities, has a vulnerability that allows Server-Side Request Forgery (SSRF) exploitation. Prior to version 0.8.26, the SSRF defenses fail when handling URLs with IPv6 notation directed to private addresses, such as http://[::1]. This oversight enables attackers to bypass security measures, potentially leading to unauthorized access and data exposure. Users are advised to upgrade to version 0.8.26 where this vulnerability has been addressed.

Affected Version(s)

CodeWhale < 0.8.26

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.