Vulnerability Description
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in URL as http://[::1], the SSRF defenses do not work. This vulnerability is fixed in 0.8.26.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-88gh-2526-gfrr
- https://github.com/Hmbown/DeepSeek-TUI/blob/15f62e3e93d842f30b428877819ebc1c8cb9
- https://github.com/Hmbown/DeepSeek-TUI/releases/tag/v0.8.26
- https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-88gh-2526-gfrr
FAQ
What is CVE-2026-45373?
CVE-2026-45373 is a vulnerability with a CVSS score of 7.4 (HIGH). CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in URL as http...
How severe is CVE-2026-45373?
CVE-2026-45373 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45373?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.