Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CodeWhale Multiple Critical Vulnerabilities in v0.8.37-0.8.63

Multiple critical vulnerabilities were discovered in CodeWhale affecting versions 0.8.37 through 0.8.63, including symlink-following leading to file leaks, auto-approved shell interaction enabling privilege escalation, argument injection in git_show allowing unauthorized file writes, environment variable leakage in JavaScript execution, and auto-approved arbitrary Python execution. All vulnerabilities were fixed in version 0.8.64.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Critical remote code execution and privilege escalation vulnerabilities affecting the CodeWhale coding agent. Multiple tools with auto-approval override user security policies, allowing model-induced arbitrary code execution, file writes, and data leaks without user consent.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-w7wx-5q49-r59w
  2. github.comhttps://github.com/advisories/GHSA-g29h-pfmp-qp9r
  3. github.comhttps://github.com/advisories/GHSA-7j5w-7r7x-9v27
  4. github.comhttps://github.com/advisories/GHSA-h539-c7r8-3xq4
  5. github.comhttps://github.com/advisories/GHSA-wrj3-vj8c-784f