Privilege Escalation Vulnerability in CodeWhale by Hmbown
CVE-2026-75857

7.3HIGH

Key Information:

Vendor

Hmbown

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-75857?

CodeWhale versions between 0.8.41 and 0.8.64 exhibit a critical flaw in the exec_shell_interact tool that allows an attacker to execute arbitrary commands at the privilege level of a long-running approved interactive shell without an approval prompt. This vulnerability occurs due to a misconfiguration in the approval requirement, enabling malicious users to leverage untrusted content to inject and execute harmful commands. Users are advised to upgrade to version 0.8.64 or later to mitigate this risk effectively.

Affected Version(s)

CodeWhale 0.3.10 < 0.8.41

CodeWhale 0.3.10 < 0.8.41

CodeWhale 0.8.41 < 0.8.64

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sai-sh
.