Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CodeWhale Multiple Vulnerabilities in Versions 0.8.41-0.8.63

CodeWhale versions 0.8.41 through 0.8.63 contain three critical vulnerabilities allowing arbitrary code execution and file writes through prompt injection: auto-approval bypass in exec_shell_interact and rlm_eval tools, and argument injection in git_show tool.

Disclosed 18 August 2026 · Record updated 13 September 2026

Impact

Attackers can execute arbitrary commands at user privilege level via prompt injection in untrusted content, with potential for privilege escalation, code execution, and arbitrary file writes to sensitive locations.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-75857
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-75858
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-75913