Path Traversal Vulnerability in CodeWhale by Hmbown
CVE-2026-75914
8.7HIGH
What is CVE-2026-75914?
CodeWhale versions prior to 0.8.64 are susceptible to a path traversal vulnerability within the image_analyze tool. This issue arises because the tool does not properly canonicalize symbolic links before accessing files. Consequently, an attacker could potentially create malicious workspace symlinks directed at external files with image extensions. By doing so, they may leak sensitive file bytes to the vision endpoint, bypassing the need for direct user approval, and posing a significant security risk.
Affected Version(s)
CodeWhale 0.8.32 < 0.8.41
CodeWhale 0.8.32 < 0.8.41
CodeWhale 0.8.41 < 0.8.64
