Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2533▼ 405 respecto a la semana anterior
Críticas / altas1319▲ 38 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

58 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.68%—CodewhaleAI18/8/20268/9/2026
CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. Attackers can craft malicious JavaScript code executed by the tool to read process.env and leak API keys, cloud credentials,…
AplazadaAlta (8.7)0.53%—CodewhaleAI18/8/20268/9/2026
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to leak file bytes to the vision endpoint without user approval.
AplazadaAlta (8.5)0.48%—Codewhale TUIAI18/8/20268/9/2026
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag.…
AplazadaAlta (8.3)0.45%—CodewhaleAI18/8/20268/9/2026
CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values like --contents=/path/to/file to exfiltrate sensitive files such as SSH keys and…
AplazadaAlta (8.5)0.25%—CodewhaleAI18/8/20268/9/2026
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a repository. When a user clones and opens the repository in CodeWhale,…
AplazadaAlta (8.7)0.53%—CodewhaleAI18/8/20268/9/2026
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system…
AplazadaAlta (8.5)0.36%—CodewhaleAICodewhale-tuiAI18/8/20268/9/2026
CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine treats as 'never prompt,' causing arbitrary model-supplied Python code to run in a…
AplazadaAlta (7.3)0.15%—CodewhaleAI18/8/20268/9/2026
CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-executing tools, so LLM-controlled stdin is written into an already-approved…
AplazadaCrítica (9.2)0.50%—CodewhaleAI18/8/20268/9/2026
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing requests to internal IP addresses and…
AplazadaCrítica (9.6)0.47%—CodewhaleAI28/5/202617/6/2026
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:1499: self.allow_shell.unwrap_or(true)) and auto_approve defaults to true (task_manager.rs:297: auto_approve: Some(true)).…
AplazadaAlta (7.4)0.42%—CodewhaleAI28/5/202617/6/2026
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in‌‌ URL‌ as http://[::1], the SSRF defenses do not work. This vulnerability is fixed in 0.8.26.
AplazadaCrítica (9.6)0.69%—CodewhaleAI28/5/202617/6/2026
CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user approval prompt. cargo test compiles and executes arbitrary code: test binaries, build.rs build scripts, and proc…
AplazadaAlta (7.4)0.37%—Deepseek CodewhaleAI28/5/202617/6/2026
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against a restricted-IP blocklist (is_restricted_ip()) to prevent SSRF attacks against internal services (cloud metadata endpoints, localhost, private networks). However, the…
AnalizadaMedia (6.9)0.68%—Icewhale Casaos2/1/202630/9/2026
CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information. The /v1/users/image endpoint can be abused with a user-controlled path parameter to access files under /var/lib/casaos/1/, which…
AnalizadaCrítica (9.1)0.29%—Navercorp Whale30/12/202517/6/2026
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
AnalizadaAlta (7.5)0.16%—Navercorp Whale30/12/202530/9/2026
Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
AnalizadaMedia (6.5)0.24%—Hackerwhale Restaurant Website Restoran19/11/202517/6/2026
Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.
AnalizadaAlta (7.5)0.37%—Navercorp Whale16/10/202517/6/2026
Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.
AnalizadaAlta (7.5)0.21%—Navercorp Whale16/10/202517/6/2026
Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.
AnalizadaCrítica (9.8)0.50%—Navercorp Whale16/10/202530/9/2026
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
AplazadaMedia (4.9)0.30%—Flowdee ClickwhaleAI20/9/202517/6/2026
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to SQL Injection via the export_csv() function in all versions up to, and including, 2.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
AnalizadaAlta (7.5)0.18%—Navercorp Whale4/7/202517/6/2026
Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment.
AnalizadaCrítica (9.8)0.41%—Navercorp Whale4/7/202517/6/2026
Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.
ModificadaAlta (8.8)0.37%—Flowdee Clickwhale7/5/202517/6/2026
Missing Authorization vulnerability in ClickWhale ClickWhale clickwhale allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ClickWhale: from n/a through <= 2.4.6.
ModificadaAlta (8.8)0.18%—Flowdee Clickwhale25/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ClickWhale ClickWhale clickwhale allows Cross Site Request Forgery.This issue affects ClickWhale: from n/a through <= 2.4.3.