{"data":{"id":"c203e876-a871-43b4-bf37-9e3d1a6f20d7","title":"GHSA-gx45-xrj5-g6c4: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository","summary":"CodeWhale versions before 0.8.64 have a vulnerability where a malicious config file (`.codewhale/config.toml`) in a cloned repository can secretly enable the `allow_shell` setting, giving an AI model the ability to run arbitrary shell commands on a user's computer without their knowledge. This bypasses the security boundary that `allow_shell` was designed to protect, since the setting can be enabled by repository maintainers without the user explicitly opting in.","solution":"Users should upgrade to CodeWhale version 0.8.64 or later, which contains the fix in commit 43563356b98c6b993085554da82e77370160a31c.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-gx45-xrj5-g6c4","publishedAt":"2026-09-04T18:14:09.000Z","cveId":"CVE-2026-75911","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["codewhale@>= 0.8.41, < 0.8.64 (fixed: 0.8.64)","codewhale-tui@>= 0.8.41, < 0.8.64 (fixed: 0.8.64)","deepseek-tui@>= 0.8.6, < 0.8.41 (fixed: 0.8.41)","deepseek-tui@>= 0.8.6, <= 0.8.41"],"affectedVendors":[],"affectedVendorsRaw":["CodeWhale","DeepSeek"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00174,"patchAvailable":true,"disclosureDate":"2026-09-04T18:14:09.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}