Hunter Bown CodeWhale是Hunter Bown个人开发者的一个开源编程智能体。 Hunter Bown CodeWhale 0.8.64之前版本存在服务端请求伪造漏洞,该漏洞源于DNS固定逻辑未能阻止时间检查与使用时间攻击,攻击者可通过操纵DNS响应使初始解析检查失败并在二次请求时成功,允许请求内部IP地址并绕过服务端请求伪造缓解措施。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-75913 | 9.3 CRITICAL | CodeWhale before 0.8.64 Argument Injection via git_show |
| CVE-2026-75858 | 7.8 HIGH | CodeWhale rlm_eval before 0.8.64 Remote Code Execution |
| CVE-2026-75911 | 7.8 HIGH | CodeWhale before 0.8.64 Remote Code Execution via allow_shell |
| CVE-2026-75915 | 7.5 HIGH | CodeWhale before 0.8.64 Environment Variable Leak via js_execution |
| CVE-2026-75914 | 7.5 HIGH | CodeWhale before 0.8.64 Path Traversal via image_analyze symlink |
| CVE-2026-75859 | 7.5 HIGH | CodeWhale before 0.8.64 Arbitrary File Read via instructions |
| CVE-2026-75912 | 7.4 HIGH | CodeWhale before 0.8.64 Argument Injection via git_blame |
| CVE-2026-75857 | 7.0 HIGH | CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact |
No comments yet