THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h539-c7r8-3xq4 (high) — CodeWhale: js_execution leaks parent environment to model context via missing env scrub

[GHSA] GHSA-h539-c7r8-3xq4 (high) — CodeWhale: js_execution leaks parent environment to model context via missing env scrub

highgithub_advisoriesPublished 2026-09-04

GHSA-h539-c7r8-3xq4 Severity: high CVE: CVE-2026-75915

CodeWhale: js_execution leaks parent environment to model context via missing env scrub

### Maintainer resolution

The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e. Users should upgrade to 0.8.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h539-c7r8-3xq4