{"data":{"id":"1ff4620f-ad27-4634-9d79-0a4878050327","title":"GHSA-h539-c7r8-3xq4: CodeWhale: js_execution leaks parent environment to model context via missing env scrub","summary":"CodeWhale's js_execution tool fails to scrub sensitive environment variables (like API keys and cloud credentials) before running model-provided JavaScript code, allowing these secrets to leak back to the AI model through the tool's output. Other tools in the same codebase use an environment allowlist (child_env helper) to prevent this, but js_execution was added four days after that security fix and never implemented it.","solution":"Users should upgrade to version 0.8.64 or later. The fix is contained in commit 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e, which adds the missing child_env scrubber to js_execution.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-h539-c7r8-3xq4","publishedAt":"2026-09-04T18:03:08.000Z","cveId":"CVE-2026-75915","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["data_extraction","pii_leakage"],"issueType":"vulnerability","affectedPackages":["codewhale@>= 0.8.41, < 0.8.64 (fixed: 0.8.64)","codewhale-tui@>= 0.8.41, < 0.8.64 (fixed: 0.8.64)","deepseek-tui@>= 0.8.32, < 0.8.41 (fixed: 0.8.41)","deepseek-tui@>= 0.8.32, <= 0.8.41"],"affectedVendors":[],"affectedVendorsRaw":["CodeWhale"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00504,"patchAvailable":true,"disclosureDate":"2026-09-04T18:03:08.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}