THREAT OPS › Threat News › [GHSA] GHSA-h539-c7r8-3xq4 (high) — CodeWhale: js_execution leaks parent environment to model context via missing env scrub
[GHSA] GHSA-h539-c7r8-3xq4 (high) — CodeWhale: js_execution leaks parent environment to model context via missing env scrub
GHSA-h539-c7r8-3xq4 Severity: high CVE: CVE-2026-75915
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e. Users should upgrade to 0.8.
MITRE ATT&CK techniques
Indicators of compromise
- 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25esha1
- CVE-2026-75915cve
Original source: https://github.com/advisories/GHSA-h539-c7r8-3xq4