crates.io
codewhale-tui
9 Total advisories
9 Vulnerabilities
0 Malware
Dependency scanning
Check whether codewhale-tui is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.4
CVE-2026-75912
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
HIGH 8.6
CVE-2026-75856
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
HIGH 7.8
CVE-2026-75911
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
HIGH 7.5
CVE-2026-75859
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
HIGH 7.8
CVE-2026-75858
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
HIGH 7.5
CVE-2026-75915
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
CRITICAL 9.3
CVE-2026-75913
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
HIGH 7.0
CVE-2026-75857
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
HIGH 7.5
CVE-2026-75914
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
Browse more crates.io advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes