GHSA-g29h-pfmp-qp9r: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
Summary
CodeWhale's `exec_shell_interact` function has a privilege escalation vulnerability where it sends commands controlled by an AI model into an already-approved interactive shell (like Python REPL or MySQL) without requiring user approval. An attacker can use prompt injection (tricking the AI by hiding instructions in its input) to make the model send malicious commands that execute at whatever privilege level that shell has, potentially allowing root or remote command execution.
Solution / Mitigation
Users should upgrade to version 0.8.64 or later, which contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381.
Vulnerability Details
EPSS: 0.1%
Yes
September 4, 2026
Classification
Taxonomy References
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-g29h-pfmp-qp9r
First tracked: September 4, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%