Insecure Defaults in CodeWhale Coding Agent Affecting DeepSeek Plus MiMo
CVE-2026-45374

9.6CRITICAL

Key Information:

Vendor

Hmbown

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-45374?

CodeWhale, a coding agent designed to enhance programming tasks, exhibits a vulnerability in its task_create tool prior to version 0.8.26. The tool spawns durable sub-agents that are inherently flawed due to insecure default configurations: allow_shell is set to true and auto_approve is fully enabled. Consequently, when a user grants approval for a seemingly benign task_create call, they inadvertently provide unrestricted shell access to the spawned sub-agents without adequate oversight or consent. This flaw raises serious security concerns, enabling potential exploitation by malicious actors. Users are advised to upgrade to version 0.8.26 to mitigate this risk.

Affected Version(s)

CodeWhale < 0.8.26

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.