{"data":{"id":"cc4c04c4-f102-4b0d-be86-f4228df1268c","title":"GHSA-62f5-cp2p-vq95: CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository","summary":"CodeWhale has a security vulnerability where a malicious `.codewhale/config.toml` file in a repository can read arbitrary files from a user's computer (like SSH keys or AWS credentials) by listing them in the `instructions` field, and then inject their contents into the AI model's system prompt (the instructions the AI receives). This happens because the code doesn't validate file paths or check if they're outside the project folder before reading them.","solution":"Users should upgrade to version 0.8.64 or later, which contains the fix in commit 43563356b98c6b993085554da82e77370160a31c.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-62f5-cp2p-vq95","publishedAt":"2026-09-04T18:00:37.000Z","cveId":"CVE-2026-75859","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["prompt_injection","data_extraction"],"issueType":"vulnerability","affectedPackages":["codewhale@>= 0.8.41, < 0.8.64 (fixed: 0.8.64)","codewhale-tui@>= 0.8.41, < 0.8.64 (fixed: 0.8.64)","deepseek-tui@>= 0.8.8, < 0.8.41 (fixed: 0.8.41)","deepseek-tui@>= 0.8.8, < 0.8.41"],"affectedVendors":[],"affectedVendorsRaw":["CodeWhale","DeepSeek"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00414,"patchAvailable":true,"disclosureDate":"2026-09-04T18:00:37.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":null,"llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0051"]}}