CVE-2026-75857: CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides...
Added to the CISA Known Exploited Vulnerabilities catalog on 18 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.
CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-executing tools, so LLM-controlled stdin is written into an ...
Required action: Review and patch if applicable to your AI infrastructure.