HIGH 8.7 NVD

CVE-2026-75859

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim'

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.

References

Published: 2026-08-18 · Source: NVD · Feed updated: 2026-08-18
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-18 via NVD.
vulnfeed aggregates 11140 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.