deepseek-tui
crates.io13 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting deepseek-tuipage 1 of 1
- CVE-2026-45310HIGHCVSS 7.4EG 7.4✓ Fixed in 0.8.222026-05-28
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against a restricted-IP blocklist (is_restricted_ip()) to prevent SSRF attacks against internal se…
- CVE-2026-45311CRITICALCVSS 9.6EG 9.6✓ Fixed in 0.8.232026-05-28
CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user approval prompt. cargo test compiles an…
- CVE-2026-45373HIGHCVSS 7.4EG 7.4✓ Fixed in 0.8.262026-05-28
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in URL as http://[::1], the SSRF defenses do no…
- CVE-2026-45374CRITICALCVSS 9.6EG 9.6✓ Fixed in 0.8.262026-05-28
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:1499: self.allow_shell.unwrap_or(true)) an…
- CVE-2026-75856HIGHCVSS 8.6EG 8.62026-08-18
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and …
- CVE-2026-75857HIGHCVSS 7.0EG 7.02026-08-18
CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-ex…
- CVE-2026-75858HIGHCVSS 7.8EG 7.82026-08-18
CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine treats…
- CVE-2026-75859HIGHCVSS 7.5EG 7.52026-08-18
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can sp…
- CVE-2026-75911HIGHCVSS 7.8EG 7.82026-08-18
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml f…
- CVE-2026-75912HIGHCVSS 7.4EG 7.42026-08-18
CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values l…
- CVE-2026-75913CRITICALCVSS 9.3EG 9.32026-08-18
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-optio…
- CVE-2026-75914HIGHCVSS 7.5EG 7.52026-08-18
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image exten…
- CVE-2026-75915HIGHCVSS 7.5EG 7.52026-08-18
CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. Attackers can craft malicious JavaScript cod…
Check whether deepseek-tui is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for deepseek-tui CVEs against the assets you own.
Start Free Scan →