Hunter Bown CodeWhale是Hunter Bown个人开发者的一个开源编程智能体。 Hunter Bown CodeWhale 0.8.41及之后版本和0.8.64之前版本存在输入验证错误漏洞,该漏洞源于git_show工具对模型提供的rev参数未经验证直接传入git show命令,缺少--end-of-options哨兵,可能导致攻击者通过恶意仓库结合提示注入以调用用户权限进行任意文件写入,针对敏感文件如~/.ssh/authorized_keys、~/.bashrc或~/.gitcon
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-75856 | 8.6 HIGH | CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU |
| CVE-2026-75858 | 7.8 HIGH | CodeWhale rlm_eval before 0.8.64 Remote Code Execution |
| CVE-2026-75911 | 7.8 HIGH | CodeWhale before 0.8.64 Remote Code Execution via allow_shell |
| CVE-2026-75915 | 7.5 HIGH | CodeWhale before 0.8.64 Environment Variable Leak via js_execution |
| CVE-2026-75914 | 7.5 HIGH | CodeWhale before 0.8.64 Path Traversal via image_analyze symlink |
| CVE-2026-75859 | 7.5 HIGH | CodeWhale before 0.8.64 Arbitrary File Read via instructions |
| CVE-2026-75912 | 7.4 HIGH | CodeWhale before 0.8.64 Argument Injection via git_blame |
| CVE-2026-75857 | 7.0 HIGH | CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact |
No comments yet