Arbitrary File Read Vulnerability in CodeWhale by Hmbown
CVE-2026-75859
8.7HIGH
What is CVE-2026-75859?
In CodeWhale versions prior to 0.8.64, a vulnerability exists due to inadequate validation of file paths within the project config instructions field. This flaw can be exploited by attackers through the use of a malicious .codewhale/config.toml file within a cloned repository, enabling them to read sensitive files outside the allowed workspace. The improperly handled paths can be injected into the AI system's prompt, leading to potential information exfiltration.
Affected Version(s)
CodeWhale 0.8.8 < 0.8.41
CodeWhale 0.8.8 < 0.8.41
CodeWhale 0.8.41 < 0.8.64
