Privilege Escalation Vulnerability in CodeWhale by Hmbown
CVE-2026-75857
7.3HIGH
What is CVE-2026-75857?
CodeWhale versions between 0.8.41 and 0.8.64 exhibit a critical flaw in the exec_shell_interact tool that allows an attacker to execute arbitrary commands at the privilege level of a long-running approved interactive shell without an approval prompt. This vulnerability occurs due to a misconfiguration in the approval requirement, enabling malicious users to leverage untrusted content to inject and execute harmful commands. Users are advised to upgrade to version 0.8.64 or later to mitigate this risk effectively.
Affected Version(s)
CodeWhale 0.3.10 < 0.8.41
CodeWhale 0.3.10 < 0.8.41
CodeWhale 0.8.41 < 0.8.64
