A AegiFlow
HIGHCVSS 8.5EPSS 0.3%

CVE-2026-75858

CVE-2026-75858 updated by NVD

Published
2026-09-04
Modified
2026-09-10
EPSS percentile
19%
Sources
github-advisory, nvd

Summary

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine treats as 'never prompt,' causing arbitrary model-supplied Python code to run in a python3 interpreter without consulting the user's configured --approval-policy and without any approval prompt or audit step. An attacker can induce the agent to execute arbitrary code via prompt injection in untrusted content the agent reads (a web page, fetched URL, repository file, or MCP tool result); the companion rlm_open tool can stage such content. Code runs on the user's machine at the user's privilege level. Fixed in 0.8.64.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmcodewhale0.8.64
npmdeepseek-tui0.8.41
rustcodewhale-tui0.8.64
rustdeepseek-tui

Remediation: Upgrade to 0.8.64 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.