top of page
perceptive_background_267k.jpg

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against a restricte…

Published:

27 mei 2026 om 22:00:00

Alert date:

28 mei 2026 om 19:09:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Security Tools

CodeWhale, a DeepSeek + MiMo coding agent for terminal environments, contains an SSRF vulnerability in versions prior to 0.8.22. The fetch_url tool validates initial URLs against a restricted IP blocklist to prevent SSRF attacks on internal services, but fails to re-validate redirect targets. The HTTP client (reqwest) automatically follows up to 5 redirects without applying the same SSRF protections, allowing attackers to bypass security controls and potentially access internal services including cloud metadata endpoints, localhost, and private networks. This vulnerability has been patched in version 0.8.22.

Technical details

Mitigation steps:

Affected products:

CodeWhale

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page