Fishcodetech · Muteki · CVE-2026-79623
**Name of the Vulnerable Software and Affected Versions**
FishCodeTech Muteki versions prior to 0.2.6
**Description**
An OS command injection flaw exists in the Default Local Worker Backend component within the `.claude/settings.json` file. This issue allows a remote attacker to execute arbitrary operating system commands through the manipulation of an unknown function. OS command injection is a flaw where an application passes unsafe user-supplied data to a system shell, allowing the execution of unauthorized commands.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.