THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gx45-xrj5-g6c4 (high) — CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

[GHSA] GHSA-gx45-xrj5-g6c4 (high) — CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

highgithub_advisoriesPublished 2026-09-04

GHSA-gx45-xrj5-g6c4 Severity: high CVE: CVE-2026-75911

CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

### Maintainer resolution

The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 43563356b98c6b993085554da82e77370160a31c. Use

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gx45-xrj5-g6c4