THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wrj3-vj8c-784f (high) — CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

[GHSA] GHSA-wrj3-vj8c-784f (high) — CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

highgithub_advisoriesPublished 2026-09-04

GHSA-wrj3-vj8c-784f Severity: high CVE: CVE-2026-75858

CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

### Maintainer resolution

The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users shoul

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wrj3-vj8c-784f