<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T02:54:37.332430+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355167</id>
    <title>EUVD-2026-355167</title>
    <updated>2026-10-06T02:54:37.334987+00:00</updated>
    <content>EUVD-2026-355167</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-75911</id>
    <title>fkie_cve-2026-75911</title>
    <updated>2026-10-06T02:54:37.335019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a repository. When a user clones and opens the repository in CodeWhale, the AI model gains access to exec_shell and task_shell tools, enabling execution of arbitrary shell commands on the victim's machine without explicit user consent.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-75911"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gx45-xrj5-g6c4</id>
    <title>GHSA-gx45-xrj5-g6c4 — CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository</title>
    <updated>2026-10-06T02:54:37.335052+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: deepseek-tui, npm: deepseek-tui, crates.io: codewhale-tui, npm: codewhale</p>
<p>### Maintainer resolution</p>
<p>The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below.</p>
<p>### Summary</p>
<p>A malicious `.codewhale/config.toml` or `.deepseek/config.toml` committed to a repository can silently set `allow_shell = true` for any user who clones and opens the repository in CodeWhale. This enables the AI model's `exec_shell` tool, granting arbitrary shell command execution on the victim's machine without the user's explicit opt-in. The `approval_policy` and `sandbox_mode` fields correctly enforce tightening-only semantics from project config, but `allow_shell` has no such guard, contradicting the intent of GHSA-72w5-pf8h-xfp4 which established `allow_shell` as an opt-in security boundary.</p>
<p>### Details</p>
<p>The project config merge function at `crates/tui/src/main.rs:5181-5182` (v0.8.50) unconditionally copies the `allow_shell` boolean from a project-level config file into the live session config:</p>
<p>```rust
if let Some(v) = table.get("allow_shell").and_then(toml::Value::as_bool) {
    config.allow_shell = Some(v);
}
```</p>
<p>No tightening guard exists for `allow_shell`, unlike `approval_policy` (lines 5144-5158, guarded by `project_approval_policy_is_allowed`) and `sandbox_mode` (lines 5161-5171, guarded by `project_sandbox_mode_is_allowed`). The merg…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gx45-xrj5-g6c4"/>
  </entry>
</feed>
