Insecure Defaults in CodeWhale Coding Agent Affecting DeepSeek Plus MiMo
CVE-2026-45374
9.6CRITICAL
What is CVE-2026-45374?
CodeWhale, a coding agent designed to enhance programming tasks, exhibits a vulnerability in its task_create tool prior to version 0.8.26. The tool spawns durable sub-agents that are inherently flawed due to insecure default configurations: allow_shell is set to true and auto_approve is fully enabled. Consequently, when a user grants approval for a seemingly benign task_create call, they inadvertently provide unrestricted shell access to the spawned sub-agents without adequate oversight or consent. This flaw raises serious security concerns, enabling potential exploitation by malicious actors. Users are advised to upgrade to version 0.8.26 to mitigate this risk.
Affected Version(s)
CodeWhale < 0.8.26
