{"id":"CVE-2026-45310","aliases":["GHSA-96ff-gc8g-wpvg"],"url":"https://o3.security/vulnerability/CVE-2026-45310","summary":"CodeWhale: SSRF via HTTP Redirect Bypass in fetch_url Tool","details":"CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against a restricted-IP blocklist (is_restricted_ip()) to prevent SSRF attacks against internal services (cloud metadata endpoints, localhost, private networks). However, the HTTP client (reqwest) is configured to automatically follow up to 5 redirects (reqwest::redirect::Policy::limited(5)) without re-validating the redirect target against the same SSRF protections. This vulnerability is fixed in 0.8.22.","published":"2026-05-28T17:30:09.575Z","modified":"2026-08-12T03:51:32.688353723Z","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"},"epss":{"score":0.00226,"percentile":0.13371,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"deepseek-tui","fixedVersion":"0.8.22"},{"ecosystem":"crates.io","name":"deepseek-tui-cli","fixedVersion":"0.8.22"},{"ecosystem":"npm","name":"deepseek-tui","fixedVersion":"0.8.22"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Hmbown/DeepSeek-TUI/releases/tag/v0.8.22"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45310.json"},{"type":"ADVISORY","url":"https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-96ff-gc8g-wpvg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45310"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.688353723Z"}}