Hunter Bown CodeWhale是Hunter Bown个人开发者的一个开源编程智能体。 Hunter Bown CodeWhale 0.8.64之前版本存在路径遍历漏洞,该漏洞源于image_analyze工具在读取文件前未对符号链接进行规范化处理,可能导致攻击者创建工作区符号链接指向带图像扩展名的外部文件,未经用户批准将文件字节泄露至视觉端点。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-75913 | 9.3 CRITICAL | CodeWhale before 0.8.64 Argument Injection via git_show |
| CVE-2026-75856 | 8.6 HIGH | CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU |
| CVE-2026-75858 | 7.8 HIGH | CodeWhale rlm_eval before 0.8.64 Remote Code Execution |
| CVE-2026-75911 | 7.8 HIGH | CodeWhale before 0.8.64 Remote Code Execution via allow_shell |
| CVE-2026-75915 | 7.5 HIGH | CodeWhale before 0.8.64 Environment Variable Leak via js_execution |
| CVE-2026-75859 | 7.5 HIGH | CodeWhale before 0.8.64 Arbitrary File Read via instructions |
| CVE-2026-75912 | 7.4 HIGH | CodeWhale before 0.8.64 Argument Injection via git_blame |
| CVE-2026-75857 | 7.0 HIGH | CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact |
No comments yet