Security Advisory

CVE-2026-75859

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-18 15:21:57
Last updated 2026-08-18 15:21:57
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.