THREAT OPS › Threat News › [GHSA] GHSA-62f5-cp2p-vq95 (high) — CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
[GHSA] GHSA-62f5-cp2p-vq95 (high) — CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
GHSA-62f5-cp2p-vq95 Severity: high CVE: CVE-2026-75859
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160
MITRE ATT&CK techniques
- Private KeysT1552.004
- CredentialsT1589.001
- System PromptAML.T0069.002
Indicators of compromise
- 43563356b98c6b993085554da82e77370160a31csha1
- CVE-2026-75859cve
Original source: https://github.com/advisories/GHSA-62f5-cp2p-vq95