


Perceptive Security
SOC/SIEM Consultancy

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against a restricte…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 19:09:38
Source:
nvd.nist.gov
Web Technologies, Security Tools
CodeWhale, a DeepSeek + MiMo coding agent for terminal environments, contains an SSRF vulnerability in versions prior to 0.8.22. The fetch_url tool validates initial URLs against a restricted IP blocklist to prevent SSRF attacks on internal services, but fails to re-validate redirect targets. The HTTP client (reqwest) automatically follows up to 5 redirects without applying the same SSRF protections, allowing attackers to bypass security controls and potentially access internal services including cloud metadata endpoints, localhost, and private networks. This vulnerability has been patched in version 0.8.22.
Technical details
Mitigation steps:
Affected products:
CodeWhale
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45310
https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-96ff-gc8g-wpvg
https://github.com/Hmbown/DeepSeek-TUI/releases/tag/v0.8.22
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
