CodeWhale, an AI coding-agent CLI/TUI that gives a model direct tools for shell execution, Python evaluation, git inspection, and file access, disclosed nine CVEs on 2026-09-04, all fixed in a single release (0.8.64). Every one traces to the same underlying failure mode: a tool that was supposed to require explicit user approval, stay inside the workspace, or strip sensitive data before exposing it to the model, didn’t. All nine are single-sourced (GitHub Advisory Database), so confidence is medium throughout, and none carry any exploitation evidence.
CVE-2026-75913: argument injection in git_show enables arbitrary file write
The git_show tool passes a model-supplied revision parameter directly into the underlying git show command’s argument list without validation or a separator marking the end of options. Per the GitHub Advisory Database record, because that parameter is unbounded, it can be crafted to match a git show option that redirects command output to a file path of the caller’s choosing — turning a tool the framework treats as read-only and auto-approves into a file-write primitive. CWE-73 (External Control of File Name or Path) and CWE-88 (Argument Injection). CVSS base 9.3 (critical; vector AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H). Impact: arbitrary file write or overwrite at the user’s privilege level, with attacker-influenced content, usable for persistence (modifying shell startup files or authorized-key lists) — triggered with no approval prompt because the tool is misclassified as read-only. Fixed in 0.8.64. Confidence: medium.
CVE-2026-75856: SSRF bypass via a DNS-pinning time-of-check/time-of-use gap
Per the GitHub Advisory Database record, the URL-fetch tool’s DNS-pinning check treats an initial failed DNS lookup as a signal to simply retry rather than to abort, creating a time-of-check/time-of-use gap: a malicious DNS server can fail the lookup used for the security check and then resolve the same hostname to an internal address on the lookup actually used for the request, so the request proceeds against an address the pinning check never validated. CWE-918 (SSRF). CVSS base 8.6 (high; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). Impact: a full bypass of the tool’s SSRF protections, letting an attacker induce the agent into fetching content from internal or loopback network services that should have been blocked. Fixed in 0.8.64. Confidence: medium.
CVE-2026-75858: rlm_eval auto-approves arbitrary Python execution
Per the GitHub Advisory Database record, the rlm_eval tool executes a model-supplied Python code string in a real interpreter, but its approval requirement is set to automatic rather than inheriting the framework’s default “required” setting for code-executing tools — so the approval gate is never consulted regardless of the user’s configured policy. A companion tool, rlm_open, shares the same flaw and can stage remote or local content into the same interpreter beforehand. The record notes this mirrors a previously patched flaw in a related test-running tool that was never applied to this broader pair. CWE-94 (Code Injection) and CWE-862 (Missing Authorization). CVSS base 7.8 (high; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Impact: unsandboxed arbitrary code execution at the user’s privilege level — reading credentials, modifying startup files, or reaching the network — triggerable via prompt injection from untrusted content with no approval prompt. Fixed in 0.8.64. Confidence: medium.
CVE-2026-75911: project config can silently enable shell execution
Per the GitHub Advisory Database record, the allow_shell setting, which gates whether the model’s tool registry exposes shell-execution tools at all, can be set to true by a per-project configuration file with no “tightening-only” guard preventing a project from relaxing it, and the field is missing from the deny-list that already blocks other sensitive project-scope keys. CWE-94 (Code Injection). CVSS base 7.8 (high; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Impact: a malicious or compromised repository can silently enable shell-command execution for the AI model on anyone who clones and opens it, with no explicit opt-in prompt. Fixed in 0.8.64. Confidence: medium.
CVE-2026-75859: project config instructions field enables arbitrary file read into the model’s system prompt
Per the GitHub Advisory Database record, a per-project config file can set an instructions field listing file paths to load into the model’s system prompt, and the code merging this config performs no path validation or workspace-boundary check before reading those paths — unlike the tool that resolves ordinary file-access paths, which does enforce a workspace boundary. The field is also absent from the existing deny-list for sensitive project-config keys. CWE-22 (Path Traversal) and CWE-200 (Information Exposure). CVSS base 7.5 (high; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Impact: a malicious or compromised repository can cause arbitrary files readable by the user — SSH keys, cloud credentials, environment files — to be read into the model’s context, from which they can be exfiltrated via ordinary conversation output. Fixed in 0.8.64. Confidence: medium.
CVE-2026-75914: image_analyze follows workspace symlinks, leaking external file bytes
Per the GitHub Advisory Database record, the image_analyze tool resolves its input path with a simple lexical join against the workspace directory instead of the codebase’s central path-resolution helper, which canonicalizes paths and rejects results falling outside the workspace. Because the check is purely lexical, a symlink located inside the workspace but pointing outside it passes validation, and the file is read through the followed symlink. The tool is read-only and auto-approved. CWE-22 (Path Traversal) and CWE-59 (Improper Link Resolution). CVSS base 7.5 (high; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Impact: disclosure of arbitrary file contents accessible to the user, base64-encoded and sent to the configured external vision API endpoint (and any intermediate network observer), triggerable via a workspace symlink combined with prompt injection, with no approval prompt. Fixed in 0.8.64. Confidence: medium.
CVE-2026-75915: js_execution leaks the parent process environment to the model
Per the GitHub Advisory Database record, the js_execution tool spawns a Node.js child process without applying the environment-scrubbing helper that every other code-execution tool in the codebase (shell, Python REPL, MCP launcher) uses to strip the parent environment down to a safe allowlist. The spawned process inherits the full parent environment, and model-supplied JavaScript can read it directly. CWE-200 (Information Exposure) and CWE-526 (Exposure of Sensitive Information Through Environmental Variables). CVSS base 7.5 (high; vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Impact: exposure of sensitive environment variables — LLM provider API keys, cloud credentials, source-control tokens, database connection strings — to model-supplied code, with the values then flowing into the model’s context and on to the configured LLM provider. Fixed in 0.8.64. Confidence: medium.
CVE-2026-75912: argument injection in git_blame enables arbitrary file read
Per the GitHub Advisory Database record, the git_blame tool passes a model-supplied revision parameter directly into the underlying git blame command’s argument list without validation or an end-of-options separator, and the tool is auto-approved as read-only. Because the revision argument isn’t bounded the way the file-path argument is, it can be made to match a git blame option that substitutes an arbitrary file’s contents in place of the actual repository content, echoed back verbatim in the tool’s output. CWE-88 (Argument Injection) and CWE-200 (Information Exposure). CVSS base 7.4 (high; vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). Impact: arbitrary file read, bounded only by the OS-level permissions of the invoking user, exposing files like private keys or credentials into the model’s context with no approval prompt. Fixed in 0.8.64. Confidence: medium.
CVE-2026-75857: exec_shell_interact bypasses approval for input sent to an already-open shell
Per the GitHub Advisory Database record, the exec_shell_interact tool, which writes model-generated input into the stdin of an already-running interactive shell process, overrides the framework’s default “required” approval setting for code-executing tools to automatic — so once a user approves opening any interactive shell once, every subsequent input the model sends into that shell’s stdin bypasses the approval gate entirely. CWE-269 (Improper Privilege Management). CVSS base 7.0 (high; vector AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Impact: command execution inside an already-approved interactive process at that process’s privilege level with no further prompt — severity scales with whatever the open shell holds access to (a database client, an active remote session, or a root shell). Fixed in 0.8.64. Confidence: medium.
Confidence and evidence gaps
All nine CVEs trace to exactly one source — GitHub Advisory Database — so confidence stays medium throughout; none reach high without independent corroboration. Three pairs of CVEs share an identical CVSS vector (CVE-2026-75858/CVE-2026-75911 at 7.8, and CVE-2026-75859/CVE-2026-75914/CVE-2026-75915 at 7.5); within each tied group we ordered by breadth and directness of impact rather than an arbitrary list position — for example, ranking the config field that directly enables shell execution ahead of the config field that enables file reads into a prompt, since the former is a more direct capability grant. All nine were fixed in the same 0.8.64 release, which reads as a single coordinated security review across the tool surface rather than nine independently timed disclosures — an inference from the shared fix version, not something the records state outright. Within each tied group, we ordered by directness and reach of impact rather than an arbitrary list position: CVE-2026-75858 (rlm_eval) is ranked ahead of CVE-2026-75911 (the allow_shell config flag) because the former is itself a direct, unsandboxed code-execution path, while the latter only grants a capability that still requires the model to separately invoke a shell tool. Among the three tied at 7.5, CVE-2026-75859 (the instructions config field) is ranked first because it can expose any file the config lists with no additional tool call, ahead of CVE-2026-75914 (which also depends on a workspace symlink and an external vision-API call) and CVE-2026-75915 (which depends specifically on the js_execution tool being invoked).
Why this matters
CodeWhale’s nine CVEs are a useful case study in how AI coding-agent security models actually fail in practice, not in theory: an approval gate that a handful of tools quietly opt out of, a path-resolution helper that most tools call but a few don’t, an environment-scrubbing routine every code-execution tool uses except one. Each individual gap is small and easy to miss in review — the pattern across nine of them in one codebase is what makes this worth treating as a category-level lesson rather than nine unrelated bugs. Teams building or evaluating AI coding agents should specifically check whether every tool that executes code, reads files, or spawns processes actually goes through the framework’s central approval, sandboxing, and environment-scrubbing paths, rather than assuming a security control that exists for most tools protects all of them. That’s the same underlying failure mode behind our MCP server security roundup: a tool an AI agent can call ends up doing more than its interface promises, because an approval gate, a sandbox boundary, or an input-validation check was assumed rather than actually enforced.
Frequently Asked Questions
Are any of these nine CodeWhale vulnerabilities being actively exploited? No. None are listed in any KEV catalog, and our source data contains no exploitation reports for any of them.
Which CodeWhale version fixes these issues? All nine are fixed in 0.8.64.
Do any of these require the user to do something unusual to be exposed? Several trigger through ordinary use of the tool against untrusted content: opening a cloned repository (the two project-config CVEs), asking the agent to fetch a URL (the SSRF bypass), or having the agent analyze an image or read a file that happens to be a symlink. Others require an existing interactive shell session or rely on prompt injection from content the agent reads.
Is this specific to CodeWhale, or does it affect other AI coding agents?
Our source data only covers CodeWhale (and its deepseek-tui package alias). The underlying failure pattern — approval gates, sandboxing, and environment scrubbing applied inconsistently across a growing tool surface — is a general risk category for any AI coding agent, but we have no evidence in this ledger about whether any other specific product shares these exact flaws.
Data sourced from the GitHub Advisory Database, evaluated September 2026. See more vulnerability intelligence.