THREAT OPS › Threat News › [GHSA] GHSA-7j5w-7r7x-9v27 (high) — CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
[GHSA] GHSA-7j5w-7r7x-9v27 (high) — CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
GHSA-7j5w-7r7x-9v27 Severity: high CVE: CVE-2026-75913
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05d1f28fa61b04719ca6a741020. Users should upgrade t
MITRE ATT&CK techniques
Indicators of compromise
- 9a34b5034d29f05d1f28fa61b04719ca6a741020sha1
- CVE-2026-75913cve
- CVE-2026-45374cve
- CVE-2026-45311cve
Original source: https://github.com/advisories/GHSA-7j5w-7r7x-9v27