Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🦀 crates.io📦 npm
Not in CISA KEV

CVE-2026-75857 — deepseek-tui

Fix: Hmbown/CodeWhale@57f3c89

CVE-2026-75857 is a Improper Privilege Management vulnerability in deepseek-tui. A fix is available for deepseek-tui — see the affected versions and patch details below.

CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact

Also known asGHSA-g29h-pfmp-qp9r
Published
Aug 18, 2026
Updated
Sep 10, 2026
Affected
4 pkgs
Patched
3 / 4
Exploits
None indexed
Exploitation data as of Sep 30, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
  • A successful exploit gives an attacker total control of the affected component, not partial access.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-75857.

EPSS Exploitation Probability

via FIRST.org ↗
0.2%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs4th percentile — riskier than 4% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

4 pkgs affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, a proxy for how much of the ecosystem is exposed.

deepseek-tuicrates.io
705downloads / week

Description

Maintainer resolution

The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below.

Summary

exec_shell is correctly approval-gated. Its sibling exec_shell_interact returns ApprovalRequirement::Auto, so when the model writes input into a shell the user already approved (a python3 -i REPL, mysql, ssh, sudo -i, etc.), no prompt fires. Inside those processes, "stdin" is the command surface, so the model gets to run commands at whatever privilege that process holds. The user approved opening the shell once, for a stated purpose; the input that then runs in it is chosen by the model, and can be steered by any prompt injection the agent ingests afterward.

Details

The vulnerability requires two ordinary preconditions: shell tools are enabled (the normal config for using CodeWhale as a coding agent), and the session already has one approved long-running interactive process. After that, any untrusted content the agent reads can drive a exec_shell_interact call.

crates/tui/src/tools/shell.rs:2834-2910:

fn capabilities(&self) -> Vec<ToolCapability> {
    vec![ToolCapability::ExecutesCode]
}

fn approval_requirement(&self) -> ApprovalRequirement {
    ApprovalRequirement::Auto          // overrides the Required-for-ExecutesCode default
}

async fn execute(&self, input: Value, context: &ToolContext) -> Result<ToolResult, ToolError> {
    let task_id = required_task_id(&input)?;
    let close_stdin = optional_bool(&input, "close_stdin", false);
    let interaction_input = input
        .get("input").or_else(|| input.get("stdin")).or_else(|| input.get("data"))  // LLM-controlled
        .and_then(serde_json::Value::as_str).unwrap_or("");
    {
        let mut manager = context.shell_manager.lock()...;
        if !interaction_input.is_empty() || close_stdin {
            manager.write_stdin(task_id, interaction_input, close_stdin)...;          // no prompt
        }
    }
    ...
}

Same gate as the rlm_eval finding: the Auto at approval_requirement() makes approval_required false at engine.rs:845, so the --approval-policy is never consulted for the stdin write. The trait default at spec.rs:632 would have been Required. The tool is registered unconditionally (registry.rs:527), and an alias exec_interact on the same struct is registered at registry.rs:530, so a fix must cover both names (it does, since they share ShellInteractTool).

PoC

  1. User asks the agent to open a REPL; the model calls exec_shell command="python3 -i"; the user sees and approves it once.
  2. Later in the session, untrusted content (a fetched page, an MCP result, a repo AGENTS.md) instructs the model to send a payload to the open REPL.
  3. The model calls exec_shell_interact task_id=<repl> input="import os; os.system('...')\n". No prompt fires; Python runs it.

Driving the interactive TUI through a pty and scanning the output for an approval dialog shows the only Approval needed: lines are for the initial exec_shell; exec_shell_interact never produces one, while a sentinel file proves the injected input ran.

When the approved process is privileged, the reach scales with it: mysql -u root becomes arbitrary SQL, ssh host becomes commands on the remote host, sudo -i becomes root — none re-prompted.

Impact

Code or command execution inside an already-approved process, at that process's privilege level, with no prompt for the escalating input. Lower severity than the rlm_eval finding because it needs a prior user approval of an interactive shell, but higher reach when that shell is privileged.

Credit

sai-sh

Affected Packages

4 total 3 fixed
EcosystemPackageVulnerable rangeFix
🦀crates.iodeepseek-tui≥ 0.3.10No fix
🦀crates.iocodewhale-tui≥ 0.8.41&&< 0.8.640.8.64cargo update -p codewhale-tui --precise 0.8.64
📦npmdeepseek-tui≥ 0.3.10&&< 0.8.410.8.41npm install deepseek-tui@0.8.41
📦npmcodewhale≥ 0.8.41&&< 0.8.640.8.64npm install codewhale@0.8.64

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for deepseek-tui, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    No patched version of deepseek-tui has shipped for CVE-2026-75857 yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.

  3. Workarounds

    Close the privilege gap rather than the entry point: audit which accounts, roles and service identities can reach the affected operation, drop the component to the least privilege it actually needs, and review file and directory permissions created by earlier installs — a default left in place is what makes this reachable.

Frequently Asked Questions

### Maintainer resolution The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 57f3c89471e27ac4032d9791f6885e5d4408c381. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. ### Summary `exec_shell` is correctly approval-gated. Its sibling `exec_shell_interact` returns `ApprovalRequirement::Auto`, so when the model writes input into a shell the user already approved (a `python3 -i` REPL, `mysql`, `ssh`, `sudo -i`, etc.), no prompt fires. Inside those
O3 Security · Impact-Aware SCA

Is CVE-2026-75857 in your dependencies?

Find it across crates.io, npm, including transitive dependencies.

CVE-2026-75857: Fixed in 0.8.64 | O3 Security