codewhale-tui vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-75911Highdeepseek-tui: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repositoryCVE-2026-75858Highdeepseek-tui: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)CVE-2026-75912Highdeepseek-tui: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without ApprovalCVE-2026-75856Criticaldeepseek-tui: CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinningCVE-2026-75915Highdeepseek-tui: CodeWhale: js_execution leaks parent environment to model context via missing env scrubCVE-2026-75913Highdeepseek-tui: CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without ApprovalCVE-2026-75857Highdeepseek-tui: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)CVE-2026-75859Highdeepseek-tui: CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repositoryCVE-2026-75914Highdeepseek-tui: CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes

Stop the waste.
Protect your environment with Kodem.