THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c6mw-8xh8-gpq6 (high) — CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval

[GHSA] GHSA-c6mw-8xh8-gpq6 (high) — CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval

highgithub_advisoriesPublished 2026-09-04

GHSA-c6mw-8xh8-gpq6 Severity: high CVE: CVE-2026-75912

CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval

### Maintainer resolution

The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade t

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c6mw-8xh8-gpq6