Skip to content
Threat Feed

Tag

Developer-Tools

7 briefs RSS
high advisory

Argument Injection Vulnerability in CodeWhale git_show Tool

An argument injection vulnerability (CVE-2026-75913) in the CodeWhale git_show tool allows attackers to perform arbitrary file writes under the user's privilege level by manipulating the 'rev' parameter.

codewhale +3 remote-code-execution configuration-vulnerability developer-tools vulnerability code-execution authorization-bypass
1r 2t 1c
high advisory

`datamodel-code-generator` Vulnerable to Code Injection via `default_factory` Field

The `datamodel-code-generator` library is vulnerable to code injection (CVE-2026-54653) when generating Python models from attacker-controlled schemas (e.g., JSON Schema, OpenAPI, YAML). This occurs because the `default_factory` schema field's value is interpolated directly as a raw Python expression into the generated code, allowing an attacker who controls the input schema to achieve arbitrary Python code execution within the consumer's process at module import time, affecting developers or CI pipelines that process untrusted schemas.

datamodel-code-generator code-injection supply-chain developer-tools python rce cve
1t 1i
high advisory

ForgeCode AI Pair-Programming CLI Arbitrary Code Execution via Malicious .mcp.json

CVE-2026-57860 describes an arbitrary code execution vulnerability in ForgeCode, an AI pair-programming CLI tool, where it automatically loads and executes commands specified in a repository's `.mcp.json` file upon startup without user confirmation, allowing attackers to achieve initial access and persistence on developer machines when a user runs `forge` within an untrusted, cloned repository.

ForgeCode arbitrary-code-execution cli developer-tools supply-chain
1r 2t 1c
low advisory

GitHub CLI `gh codespace jupyter` Command Remote Code Execution Vulnerability

A remote code execution vulnerability, CVE-2026-59831, has been identified in the GitHub CLI's `gh codespace jupyter` command, allowing attackers to execute arbitrary code on a user's system when connecting to a specially crafted malicious Codespace.

GitHub CLI +1 remote-code-execution vulnerability github cli codespaces developer-tools
1t 1c
high advisory

SafeInstall CLI Guard Bypass Vulnerability Allows Unauthorized Package Execution

A vulnerability in SafeInstall CLI through version 0.10.1 allows attackers to bypass its agent guard and execute unauthorized package installation or registry-provided scaffolding commands, potentially compromising developer environments.

safeinstall-cli vulnerability supply-chain developer-tools defense-evasion
2t
high advisory

Coder SSH Config Injection Vulnerability (CVE-2026-55427)

A malicious or compromised Coder server can exploit CVE-2026-55427 to inject unsanitized SSH configuration values via `coder config-ssh` into developer workstations, enabling arbitrary code execution on client machines.

Coder +3 ssh configuration-injection rce supply-chain developer-tools vulnerability
1t
critical advisory

Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

A critical vulnerability (CVE-2026-33646) in Mise allows for arbitrary code execution on victim machines via malicious `.tool-versions` files containing Tera template syntax, which are processed without trust verification, enabling silent supply chain attacks upon directory entry.

mise rce supply-chain trust-bypass code-execution developer-tools cve
1r 5t 1c