{"id":"CVE-2026-75915","aliases":["GHSA-h539-c7r8-3xq4"],"url":"https://o3.security/vulnerability/CVE-2026-75915","summary":"CodeWhale before 0.8.64 Environment Variable Leak via js_execution","details":"### Maintainer resolution\n\nThe CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below.\n\n### Summary\n\njs_execution exposes parent process environment to model-provided JavaScript\n\nThe js_execution tool spawns Node with tokio::process::Command::new without calling the child_env scrubber that exec_shell, the Python REPL, and the MCP launcher all use. Model-provided JavaScript reads process.env and the values flow back to the parent transcript as the tool's stdout, exposing API keys, cloud credentials, and forge tokens to the next model turn.\n\n### Details\n\nIn `crates/tui/src/tools/js_execution.rs` (v0.8.37, lines 91-105):\n\n```rust\nlet temp_dir = tempfile::tempdir()\n    .map_err(|e| ToolError::execution_failed(format!(\"tempdir failed: {e}\")))?;\nlet script_path = temp_dir.path().join(\"js_execution.js\");\ntokio::fs::write(&script_path, code)\n    .await\n    .map_err(|e| ToolError::execution_failed(format!(\"tempfile write failed: {e}\")))?;\n\nlet mut cmd = tokio::process::Command::new(&node);\ncmd.arg(&script_path);\ncmd.current_dir(workspace);\n\nlet output = tokio::time::timeout(Duration::from_secs(120), cmd.output())\n    .await\n    .map_err(|_| ToolError::Timeout { seconds: 120 })\n    .and_then(|res| res.map_err(|e| ToolError::execution_failed(e.to_string())))?;\n```\n\nThe Command is built without `cmd.env_clear()` and without the project's `crate::child_env::apply_to_tokio_command` helper. Every variable in the parent process environment is inherited by the spawned `node`.\n\nFor comparison, exec_shell (`crates/tui/src/tools/shell.rs:790-792`) and the Python REPL (`crates/tui/src/repl/runtime.rs:238`) both apply the scrubber:\n\n```rust\nchild_env::apply_to_command(&mut cmd, child_env::string_map_env(&exec_env.env));\n```\n\napply_to_tokio_command calls `cmd.env_clear()` and then re-installs only the keys that pass `is_allowed_parent_env_key` (PATH, HOME, USER, LANG/LC_*, TMPDIR, proxy variables, Windows toolchain context, terminal settings). Secret-bearing variables (DEEPSEEK_API_KEY, OPENAI_API_KEY, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, etc.) are not on the allowlist and are dropped before the child starts. The js_execution path bypasses both the env_clear and the allowlist.\n\nCommit history makes the gap explicit. Commit `e6d4eae fix(security): scrub child process environments` (2026-05-08) introduced child_env.rs and rewrote exec_shell, the Python REPL, the MCP launcher, and main.rs to use it. Commit `2566f3c feat(tools): add js_execution tool` (2026-05-12) added this file four days later and never picked up the helper.\n\nThe tool is described to the model and surfaced in the approval pane as \"Run model-provided JavaScript code in local Node.js execution sandbox\" (`crates/tui/src/core/engine/turn_loop.rs:1174-1176`). No sandbox is applied beyond a 120-second timeout; Node has full filesystem and network access in addition to the inherited environment. The wording understates the trust boundary that the user is being asked to cross.\n\nIn YOLO mode (`auto_approve=true`) the JS body runs without any prompt at all, so a single adversarial prompt-injection from a README, fetched web page, or MCP server output drains the parent environment to the next model turn.\n\n### PoC\n\nA standalone Cargo test reproduces the unscrubbed-env behavior. Save as `crates/tui/tests/js_execution_env_leak.rs` and run with `cargo test -p deepseek-tui --test js_execution_env_leak -- --nocapture`:\n\n```rust\nuse deepseek_tui::tools::js_execution::execute_js_execution_tool;\nuse serde_json::json;\nuse tempfile::tempdir;\n\n#[tokio::test]\nasync fn js_execution_inherits_parent_secrets() {\n    if deepseek_tui::dependencies::resolve_node().is_none() {\n        eprintln!(\"node not on PATH; skipping\");\n        return;\n    }\n    unsafe {\n        std::env::set_var(\"AWS_SECRET_ACCESS_KEY\", \"leak-marker-AKIA-EXAMPLE\");\n        std::env::set_var(\"DEEPSEEK_API_KEY\", \"leak-marker-sk-EXAMPLE\");\n    }\n    let tmp = tempdir().unwrap();\n    let result = execute_js_execution_tool(\n        &json!({\"code\": \"console.log(process.env.AWS_SECRET_ACCESS_KEY + '|' + process.env.DEEPSEEK_API_KEY)\"}),\n        tmp.path(),\n    ).await.expect(\"execute\");\n    let payload: serde_json::Value = serde_json::from_str(&result.content).unwrap();\n    let stdout = payload[\"stdout\"].as_str().unwrap_or(\"\");\n    assert!(stdout.contains(\"leak-marker-AKIA-EXAMPLE\"), \"AWS leaked: {stdout}\");\n    assert!(stdout.contains(\"leak-marker-sk-EXAMPLE\"), \"DEEPSEEK leaked: {stdout}\");\n}\n```\n\nEquivalent reproducer against the binary:\n\n```bash\nexport AWS_SECRET_ACCESS_KEY=\"leak-marker-AKIA-EXAMPLE\"\nexport DEEPSEEK_API_KEY=\"leak-marker-sk-EXAMPLE\"\ndeepseek\n# Ask the model to run:\n#   js_execution({\"code\":\"console.log(JSON.stringify(process.env))\"})\n# Approve once. The returned stdout contains every parent env value verbatim,\n# including the markers above, and is now part of the model's context for the next request.\n```\n\nThe fix is one line added next to the existing `cmd.current_dir(workspace)` call:\n\n```rust\nlet mut cmd = tokio::process::Command::new(&node);\ncmd.arg(&script_path);\ncmd.current_dir(workspace);\ncrate::child_env::apply_to_tokio_command(&mut cmd, std::iter::empty::<(&str, &str)>());\n```\n\nThis calls the existing helper with no overrides, mirroring how repl/runtime.rs spawns the Python REPL. The behavior the description string already promises (sandbox) is then partially honored: secret-bearing parent variables stay in the parent.\n\n### Impact\n\nThe tool returns parent-environment secrets to the model on a single approval, or with no approval in YOLO mode. Any variable the user has exported becomes part of the next model request and travels to the configured LLM provider's logs. Common variables that the codebase's own provider clients read from process env, and therefore the values most likely to be present, include DEEPSEEK_API_KEY, OPENAI_API_KEY, ANTHROPIC_API_KEY, MISTRAL_API_KEY, AZURE_OPENAI_API_KEY, XAI_API_KEY, GROQ_API_KEY, and TOGETHER_API_KEY. Cloud and source-control credentials commonly exported in developer shells include AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GOOGLE_APPLICATION_CREDENTIALS, GITHUB_TOKEN, GH_TOKEN, GITLAB_TOKEN, NPM_TOKEN, CARGO_REGISTRY_TOKEN, PYPI_API_TOKEN, and DATABASE_URL-style secrets. The local-sandbox wording shown at approval time understates the trust boundary, so users approving what they read as a sandboxed snippet do not anticipate that every shell-exported credential is reachable from the snippet. The remediation matches the pattern already adopted across exec_shell, the Python REPL, and the MCP launcher, so the gap is a missed call site rather than a design tradeoff.","published":"2026-08-18T15:22:02.935Z","modified":"2026-09-10T03:30:18.578807647Z","cvss":null,"epss":{"score":0.00624,"percentile":0.48298,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"deepseek-tui","fixedVersion":null},{"ecosystem":"crates.io","name":"codewhale-tui","fixedVersion":"0.8.64"},{"ecosystem":"npm","name":"deepseek-tui","fixedVersion":"0.8.41"},{"ecosystem":"npm","name":"codewhale","fixedVersion":"0.8.64"}],"fix":{"url":"https://github.com/Hmbown/CodeWhale/commit/26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e","label":"Hmbown/CodeWhale@26de44a"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75915.json"},{"type":"ADVISORY","url":"https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-h539-c7r8-3xq4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75915"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/codewhale-before-environment-variable-leak-via-js-execution"},{"type":"FIX","url":"https://github.com/Hmbown/CodeWhale/commit/26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e"},{"type":"PACKAGE","url":"https://github.com/Hmbown/CodeWhale"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:30:18.578807647Z"}}