npm

deepseek-tui

View on npm registry
11 Total advisories
11 Vulnerabilities
0 Malware

Dependency scanning

Check whether deepseek-tui is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.4
crates.io

CVE-2026-75912

CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval

HIGH 8.6
crates.io

CVE-2026-75856

CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning

HIGH 7.8
crates.io

CVE-2026-75911

CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

HIGH 7.5
crates.io

CVE-2026-75859

CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository

HIGH 7.8
crates.io

CVE-2026-75858

CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

HIGH 7.5
crates.io

CVE-2026-75915

CodeWhale: js_execution leaks parent environment to model context via missing env scrub

CRITICAL 9.3
crates.io

CVE-2026-75913

CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval

HIGH 7.0
crates.io

CVE-2026-75857

CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)

HIGH 7.5
crates.io

CVE-2026-75914

CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes

HIGH 7.4
crates.io

CVE-2026-45310

DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool

CRITICAL 9.6
crates.io

CVE-2026-45311

DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes