Description
A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element is an unknown function of the file .claude/settings.json of the component Default Local Worker Backend. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The issue was closed with the comment (translated from Chinese): "The project will be refactored and shut down."
Published: 2026-08-25
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the Default Local Worker Backend component of FishCodeTech Muteki, triggered by an unknown function in the .claude/settings.json file. By manipulating this input, a remote attacker can cause the Muteki process to execute arbitrary operating‑system commands, compromising system confidentiality, integrity, and availability. The CVSS score of 5.3 reflects a moderate severity level.

Affected Systems

FishCodeTech Muteki versions up to and including 0.2.5 are affected, with the vulnerability tied to settings.json handling via the Default Local Worker Backend; no specific post‑0.2.5 patch has been identified. Any installation of a release at or below 0.2.5 should be considered vulnerable until remediation is applied or the component is removed.

Risk and Exploitability

EPSS data is unavailable and the issue is not listed in KEV, so public exploitation metrics are limited. Nevertheless, the described remote attack requires only network access to the Muteki service and the ability to influence the settings.json handling. Successful exploitation allows an attacker to run commands with the Muteki process's privileges, install malware, exfiltrate data, or pivot to other assets. The moderate CVSS score indicates a significant risk that warrants timely mitigation.

Generated by OpenCVE AI on August 25, 2026 at 15:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Muteki to any release newer than 0.2.5 where the settings.json handling is fixed.
  • Restrict network exposure of the Muteki service so that only trusted hosts can communicate with the Default Local Worker Backend component.
  • If an update is not yet available, remove or disable the Default Local Worker Backend feature entirely or restrict its configuration file permissions so that only OS administrators can modify settings.json.

Generated by OpenCVE AI on August 25, 2026 at 15:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element is an unknown function of the file .claude/settings.json of the component Default Local Worker Backend. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The issue was closed with the comment (translated from Chinese): "The project will be refactored and shut down."
Title FishCodeTech Muteki Default Local Worker Backend settings.json os command injection
First Time appeared Fishcodetech
Fishcodetech muteki
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:fishcodetech:muteki:*:*:*:*:*:*:*:*
Vendors & Products Fishcodetech
Fishcodetech muteki
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Fishcodetech Muteki
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-25T13:30:09.438Z

Reserved: 2026-08-25T08:42:50.129Z

Link: CVE-2026-79623

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T14:16:57.620

Modified: 2026-08-25T14:16:57.620

Link: CVE-2026-79623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T15:15:04Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')