6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in 666ghj MiroFish up to 0.1.2. The impacted element is the function SimulationIPCClient.send_command of the file backend/app/services/simulation_ipc.py of the component Inter-Process Communication. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Basic Information
ID
CVE-2026-7058
Source
VulDB
Published
Apr 26, 2026 at 19:45
Affected Product
Vendor
666ghj
Product
MiroFish
Version
0.1.0
Affected Versions
666ghj MiroFish 0.1.0
666ghj MiroFish 0.1.1
666ghj MiroFish 0.1.2
666ghj MiroFish 0.1.1
666ghj MiroFish 0.1.2