


Perceptive Security
SOC/SIEM Consultancy

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 addresses, w…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 19:09:38
Source:
nvd.nist.gov
Web Technologies, Security Tools
CodeWhale, a DeepSeek + MiMo coding agent for terminal, contains an SSRF vulnerability in versions prior to 0.8.26. The vulnerability allows bypassing SSRF defenses when IPv6 addresses are provided in URL format as http://[::1]. While SSRF validation works against hostnames that resolve to private IPv6 addresses, the direct IPv6 URL format bypasses these protections. This could allow attackers to access internal services through server-side request forgery. The vulnerability has been patched in version 0.8.26.
Technical details
Mitigation steps:
Affected products:
CodeWhale
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45373
https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-88gh-2526-gfrr
https://github.com/Hmbown/DeepSeek-TUI/blob/15f62e3e93d842f30b428877819ebc1c8cb96814/crates/tui/src/tools/fetch_url.rs#L321
https://github.com/Hmbown/DeepSeek-TUI/releases/tag/v0.8.26
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
