THREAT OPS › Threat News › [GHSA] GHSA-wrj3-vj8c-784f (high) — CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
[GHSA] GHSA-wrj3-vj8c-784f (high) — CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
GHSA-wrj3-vj8c-784f Severity: high CVE: CVE-2026-75858
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users shoul
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 57f3c89471e27ac4032d9791f6885e5d4408c381sha1
- CVE-2026-75858cve
- CVE-2026-45311cve
Original source: https://github.com/advisories/GHSA-wrj3-vj8c-784f