CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to leak file bytes to the vision endpoint without user approval.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hmbown
Hmbown codewhale |
|
| Vendors & Products |
Hmbown
Hmbown codewhale |
Tue, 18 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to leak file bytes to the vision endpoint without user approval. | |
| Title | CodeWhale before 0.8.64 Path Traversal via image_analyze symlink | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T15:22:02.234Z
Reserved: 2026-08-18T15:05:54.225Z
Link: CVE-2026-75914
No data.
Status : Received
Published: 2026-08-18T16:18:23.840
Modified: 2026-08-18T16:18:23.840
Link: CVE-2026-75914
No data.
OpenCVE Enrichment
Updated: 2026-08-18T17:30:15Z