Impact
A flaw in 666ghj MiroFish version 0.1.2 and earlier allows an attacker to supply crafted input to the SimulationIPCClient.send_command method, which is then executed on the host without proper validation. This results in arbitrary command execution, violating confidentiality, integrity, and availability of the affected system. The vulnerability is classified as CWE‑74 (Command Injection) and CWE‑77 (Shell Injection). The attack can originate remotely by compromising the IPC service, which may be exposed to external networks.
Affected Systems
MiroFish (666ghj) up to and including version 0.1.2.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate to high severity. An EPSS score of 1% signals a low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw permits remote execution through the IPC interface, services exposed to untrusted clients face the risk of complete system compromise if the IPC process runs with elevated privileges. Although no publicly released exploit is documented, the advisory notes that the vulnerability has been disclosed and may already be in use.
OpenCVE Enrichment