Arbitrary File Read Vulnerability in CodeWhale by Hmbown
CVE-2026-75859

8.7HIGH

Key Information:

Vendor

Hmbown

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-75859?

In CodeWhale versions prior to 0.8.64, a vulnerability exists due to inadequate validation of file paths within the project config instructions field. This flaw can be exploited by attackers through the use of a malicious .codewhale/config.toml file within a cloned repository, enabling them to read sensitive files outside the allowed workspace. The improperly handled paths can be injected into the AI system's prompt, leading to potential information exfiltration.

Affected Version(s)

CodeWhale 0.8.8 < 0.8.41

CodeWhale 0.8.8 < 0.8.41

CodeWhale 0.8.41 < 0.8.64

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
dungNHVhust
sai-sh
.