CVE-2026-75859: Hmbown Codewhale

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.

Affected products

  • Hmbown Codewhale: from 0.8.8, before 0.8.41 (fixed in 0.8.41); from 0.8.41, before 0.8.64 (fixed in 0.8.64)

Published 2026-08-18. Last modified 2026-09-08.