Arbitrary Command Execution Vulnerability in CodeWhale by Hmbown
CVE-2026-75911

8.5HIGH

Key Information:

Vendor

Hmbown

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-75911?

CodeWhale versions prior to 0.8.64 contain a vulnerability in the processing of the allow_shell configuration parameter from project config files. This flaw facilitates the execution of arbitrary shell commands on a user's machine without their explicit consent when a malicious .codewhale/config.toml file is committed to a repository. When a user clones and opens this repo using CodeWhale, the AI model gains unauthorized access to exec_shell and task_shell tools, posing severe security risks. For remediation, users are advised to upgrade to the latest version.

Affected Version(s)

CodeWhale 0.8.6 < 0.8.41

CodeWhale 0.8.6 < 0.8.41

CodeWhale 0.8.41 < 0.8.64

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
dungNHVhust
.