Arbitrary Command Execution Vulnerability in CodeWhale by Hmbown
CVE-2026-75911
8.5HIGH
What is CVE-2026-75911?
CodeWhale versions prior to 0.8.64 contain a vulnerability in the processing of the allow_shell configuration parameter from project config files. This flaw facilitates the execution of arbitrary shell commands on a user's machine without their explicit consent when a malicious .codewhale/config.toml file is committed to a repository. When a user clones and opens this repo using CodeWhale, the AI model gains unauthorized access to exec_shell and task_shell tools, posing severe security risks. For remediation, users are advised to upgrade to the latest version.
Affected Version(s)
CodeWhale 0.8.6 < 0.8.41
CodeWhale 0.8.6 < 0.8.41
CodeWhale 0.8.41 < 0.8.64
