CVE-2026-45374

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:1499: self.allow_shell.unwrap_or(true)) and auto_approve defaults to true (task_manager.rs:297: auto_approve: Some(true)). When a user approves a task_create call (which requires ApprovalRequirement::Required), they approve what appears to be a benign work prompt. However, the spawned sub-agent silently receives unrestricted, unapproved shell access. This vulnerability is fixed in 0.8.26.
Configurations

No configuration.

History

30 May 2026, 04:17

Type Values Removed Values Added
References () https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-72w5-pf8h-xfp4 - () https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-72w5-pf8h-xfp4 -

28 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 18:16

Updated : 2026-05-30 04:17


NVD link : CVE-2026-45374

Mitre link : CVE-2026-45374

CVE.ORG link : CVE-2026-45374


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')