Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Hmbown — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting Hmbown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page documents Common Weakness Enumerations (CWE) associated with the vendor Hmbown. It aggregates a comprehensive collection of security vulnerabilities, covering historical data from the earliest recorded incidents up to the present day. By consolidating these findings, the resource provides a unified view of the threat landscape specifically tied to Hmbown’s product ecosystem. Visitors can utilize this page to track Hmbown’s security advisory timeline and monitor how quickly the vendor responds to newly disclosed flaws. You can also deepen your understanding of specific weakness classes by observing how they manifest across different Hmbown products and versions. Additionally, the page allows users to look up the complete vulnerability history of any specific product, revealing patterns in bug types and severity distributions over time. This information is critical for security analysts evaluating the long-term stability and maintenance practices of Hmbown’s offerings. The data is organized to facilitate easy comparison between products and to highlight recurring issues that may indicate systemic design flaws. Whether you are conducting a routine audit or researching a specific weakness, this aggregation serves as a central reference point for Hmbown-related security intelligence. The content is continuously updated to reflect the latest disclosures and patch releases, ensuring that users have access to the most current information available regarding the vendor’s security posture.

Top products by Hmbown: CodeWhale
CVE ID Title CVSS Severity Published
CVE-2026-75915 CodeWhale before 0.8.64 Environment Variable Leak via js_execution — CodeWhale CWE-200 7.5 High 2026-08-18
CVE-2026-75913 CodeWhale before 0.8.64 Argument Injection via git_show — CodeWhale CWE-73 9.3 Critical 2026-08-18
CVE-2026-75914 CodeWhale before 0.8.64 Path Traversal via image_analyze symlink — CodeWhale CWE-22 7.5 High 2026-08-18
CVE-2026-75912 CodeWhale before 0.8.64 Argument Injection via git_blame — CodeWhale CWE-88 7.4 High 2026-08-18
CVE-2026-75911 CodeWhale before 0.8.64 Remote Code Execution via allow_shell — CodeWhale CWE-94 7.8 High 2026-08-18
CVE-2026-75859 CodeWhale before 0.8.64 Arbitrary File Read via instructions — CodeWhale CWE-22 7.5 High 2026-08-18
CVE-2026-75858 CodeWhale rlm_eval before 0.8.64 Remote Code Execution — CodeWhale CWE-94 7.8 High 2026-08-18
CVE-2026-75856 CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU — CodeWhale CWE-918 8.6 High 2026-08-18
CVE-2026-75857 CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact — CodeWhale CWE-269 7.0 High 2026-08-18
CVE-2026-45311 CodeWhale: run_tests Tool Enables RCE via Malicious Repository Without Approval — CodeWhale CWE-94 9.6 Critical 2026-05-28
CVE-2026-45310 CodeWhale: SSRF via HTTP Redirect Bypass in fetch_url Tool — CodeWhale CWE-918 7.4 High 2026-05-28
CVE-2026-45373 CodeWhale: SSRF‌ IPV6 bypass — CodeWhale CWE-918 7.4 High 2026-05-28
CVE-2026-45374 CodeWhale: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files — CodeWhale CWE-94 9.6 Critical 2026-05-28

This page lists every published CVE security advisory associated with Hmbown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.