CVE-2026-75913: External Control of File Name or Path in Hmbown CodeWhale
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag. Because the tool is registered as auto-approved and advertised as read-only, an attacker (via a malicious repository combined with prompt injection) can cause an unprompted arbitrary file write at the privilege of the invoking user, targeting sensitive files such as ~/.ssh/authorized_keys, ~/.bashrc, or ~/.gitconfig. Fixed in 0.8.64 by adding rev validation.
AI Analysis
Technical Summary
CodeWhale (codewhale / codewhale-tui) versions >=0.8.41 and <0.8.64 have an argument injection vulnerability in the git_show tool. The rev parameter, supplied by the model, is passed directly into the git show argv without an --end-of-options sentinel, allowing values starting with --output= to be interpreted as git flags. Since the tool is auto-approved and advertised as read-only, an attacker can exploit this via a malicious repository combined with prompt injection to cause an unprompted arbitrary file write with the privileges of the invoking user. This can target sensitive files such as ~/.ssh/authorized_keys, ~/.bashrc, or ~/.gitconfig. The vulnerability is fixed in version 0.8.64 by adding validation to the rev parameter.
Potential Impact
An attacker can cause arbitrary file writes on the system with the privileges of the user running CodeWhale. This can lead to overwriting critical configuration or authentication files, potentially enabling further compromise or persistence. The vulnerability does not require privileges or user interaction beyond invoking the vulnerable tool with a crafted repository and prompt injection.
Mitigation Recommendations
A fix is available in CodeWhale version 0.8.64, which adds validation of the rev parameter to prevent argument injection. Users should upgrade to version 0.8.64 or later to remediate this vulnerability. No other official remediation or temporary fixes are documented. Patch status is not explicitly confirmed beyond the fix in 0.8.64; users should verify with vendor advisories.
CVE-2026-75913: External Control of File Name or Path in Hmbown CodeWhale
Description
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag. Because the tool is registered as auto-approved and advertised as read-only, an attacker (via a malicious repository combined with prompt injection) can cause an unprompted arbitrary file write at the privilege of the invoking user, targeting sensitive files such as ~/.ssh/authorized_keys, ~/.bashrc, or ~/.gitconfig. Fixed in 0.8.64 by adding rev validation.
CVSS v4.0
Score 8.5high
Affected software
Hmbown
CodeWhale
Hmbown
CodeWhale
pkg:github/hmbown/codewhale-tuiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CodeWhale (codewhale / codewhale-tui) versions >=0.8.41 and <0.8.64 have an argument injection vulnerability in the git_show tool. The rev parameter, supplied by the model, is passed directly into the git show argv without an --end-of-options sentinel, allowing values starting with --output= to be interpreted as git flags. Since the tool is auto-approved and advertised as read-only, an attacker can exploit this via a malicious repository combined with prompt injection to cause an unprompted arbitrary file write with the privileges of the invoking user. This can target sensitive files such as ~/.ssh/authorized_keys, ~/.bashrc, or ~/.gitconfig. The vulnerability is fixed in version 0.8.64 by adding validation to the rev parameter.
Potential Impact
An attacker can cause arbitrary file writes on the system with the privileges of the user running CodeWhale. This can lead to overwriting critical configuration or authentication files, potentially enabling further compromise or persistence. The vulnerability does not require privileges or user interaction beyond invoking the vulnerable tool with a crafted repository and prompt injection.
Mitigation Recommendations
A fix is available in CodeWhale version 0.8.64, which adds validation of the rev parameter to prevent argument injection. Users should upgrade to version 0.8.64 or later to remediate this vulnerability. No other official remediation or temporary fixes are documented. Patch status is not explicitly confirmed beyond the fix in 0.8.64; users should verify with vendor advisories.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-18T15:05:54.225Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a847ba0c6e8be0332665559
Added to database: 08/18/2026, 15:34:56 UTC
Last enriched: 08/18/2026, 15:49:52 UTC
Last updated: 10/02/2026, 02:46:06 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.