Impact
The flaw exists in the Default Local Worker Backend component of FishCodeTech Muteki, triggered by an unknown function in the .claude/settings.json file. By manipulating this input, a remote attacker can cause the Muteki process to execute arbitrary operating‑system commands, compromising system confidentiality, integrity, and availability. The CVSS score of 5.3 reflects a moderate severity level.
Affected Systems
FishCodeTech Muteki versions up to and including 0.2.5 are affected, with the vulnerability tied to settings.json handling via the Default Local Worker Backend; no specific post‑0.2.5 patch has been identified. Any installation of a release at or below 0.2.5 should be considered vulnerable until remediation is applied or the component is removed.
Risk and Exploitability
EPSS data is unavailable and the issue is not listed in KEV, so public exploitation metrics are limited. Nevertheless, the described remote attack requires only network access to the Muteki service and the ability to influence the settings.json handling. Successful exploitation allows an attacker to run commands with the Muteki process's privileges, install malware, exfiltrate data, or pivot to other assets. The moderate CVSS score indicates a significant risk that warrants timely mitigation.
OpenCVE Enrichment