CVE-2026-79623 | FishCodeTech Muteki up to 0.2.5 Default Local Worker Backend .claude/settings.json os command injection
A vulnerability was found in FishCodeTech Muteki up to 0.2.5. It has been rated as critical. The affected element is an unknown function of the file .claude/settings.json of the component Default Local Worker Backend. The manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-79623. The attack can be initiated remotely. Additionally, an exploit exists.
The issue was closed with the comment (translated from Chinese): “The project will be refactored and shut down.”VulDB Recent EntriesRead More