{"data":{"id":"27b7327e-d453-4e3d-bba3-73780bbb2338","title":"GHSA-c6mw-8xh8-gpq6: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval","summary":"The `git_blame` tool in DeepSeek-TUI has a vulnerability where it passes user input directly to a git command without validation, allowing an attacker to read arbitrary files on the system. By injecting a specially crafted argument like `--contents=/path/to/secret`, an attacker can trick the tool into displaying the contents of sensitive files (such as SSH keys or credentials) in the chat transcript, even though the tool is labeled as read-only and normally restricted to the workspace.","solution":"Users should upgrade to version 0.8.64 or later, which contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-c6mw-8xh8-gpq6","publishedAt":"2026-09-04T18:11:45.000Z","cveId":"CVE-2026-75912","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":["codewhale@>= 0.8.41, < 0.8.64 (fixed: 0.8.64)","codewhale-tui@>= 0.8.41, < 0.8.64 (fixed: 0.8.64)","deepseek-tui@>= 0.3.27, < 0.8.41 (fixed: 0.8.41)","deepseek-tui@>= 0.3.27, <= 0.8.41"],"affectedVendors":[],"affectedVendorsRaw":["DeepSeek-TUI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00322,"patchAvailable":true,"disclosureDate":"2026-09-04T18:11:45.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0051"]}}