{"data":{"id":"b77be339-d4d4-4603-817b-0786dbd8e9d0","title":"GHSA-g29h-pfmp-qp9r: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)","summary":"CodeWhale's `exec_shell_interact` function has a privilege escalation vulnerability where it sends commands controlled by an AI model into an already-approved interactive shell (like Python REPL or MySQL) without requiring user approval. An attacker can use prompt injection (tricking the AI by hiding instructions in its input) to make the model send malicious commands that execute at whatever privilege level that shell has, potentially allowing root or remote command execution.","solution":"Users should upgrade to version 0.8.64 or later, which contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-g29h-pfmp-qp9r","publishedAt":"2026-09-04T18:02:10.000Z","cveId":"CVE-2026-75857","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":["codewhale@>= 0.8.41, < 0.8.64 (fixed: 0.8.64)","codewhale-tui@>= 0.8.41, < 0.8.64 (fixed: 0.8.64)","deepseek-tui@>= 0.3.10, < 0.8.41 (fixed: 0.8.41)","deepseek-tui@>= 0.3.10, <= 0.8.41"],"affectedVendors":[],"affectedVendorsRaw":["CodeWhale"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00121,"patchAvailable":true,"disclosureDate":"2026-09-04T18:02:10.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0051"]}}