CVE-2026-75859
Last modified
CVE-2026-75859 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Hmbown | CodeWhale | >= 0.8.8, < 0.8.41 |
| Hmbown | CodeWhale | >= 0.8.41, < 0.8.64 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-75859?
How severe is CVE-2026-75859?
How do I fix CVE-2026-75859?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-75853ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcade…8.8
- CVE-2026-75854ArcadeDB versions before 26.8.1 contain a missing authentica…9.8
- CVE-2026-75855ArcadeDB versions before 26.8.1 fail to sanitize database na…8.7
- CVE-2026-75856CodeWhale before 0.8.64 contains a server-side request forge…8.6
- CVE-2026-75857CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerab…7
- CVE-2026-75858CodeWhale (packages codewhale / codewhale-tui) versions >= 0…7.8
- CVE-2026-7586A weakness has been identified in Open5GS up to 2.7.7. Affec…4.3
- CVE-2026-75860The JSON Options WordPress plugin through 0.0.4 does not hav…9.8
- CVE-2026-75861The Ultimate Gift Cards for WooCommerce WordPress plugin bef…6.5
- CVE-2026-75862Photoshop Desktop is affected by an Integer Overflow or Wrap…7.8
- CVE-2026-75863Photoshop Desktop is affected by an Integer Overflow or Wrap…7.8
- CVE-2026-75865The WPLP Cookie Consent – Cookie Banner & Consent Management…9.8
Are you affected by CVE-2026-75859?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
