0X4M4 Hexstrike Ai vulnerabilities
5 known vulnerabilities affecting 0x4m4/hexstrike_ai.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4
Vulnerabilities
Page 1 of 1
CVE-2025-35028P2CRITICALCVSS 9.1v33267047667b9accfbf0fdac1c1c7ff12f3a55122025-11-30
CVE-2025-35028 [CRITICAL] CWE-78 CVE-2025-35028: By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the
By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the defa
nvd
CVE-2026-90619P2HIGHCVSS 7.3vd689933ff579d839c676c82b231f8e98326c5f042026-09-14
CVE-2026-90619 [HIGH] CWE-77 CVE-2026-90619: A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.
A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code/script leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed
nvd
CVE-2026-90690P3HIGHCVSS 7.3vd689933ff579d839c676c82b231f8e98326c5f042026-09-14
CVE-2026-90690 [HIGH] CWE-77 CVE-2026-90690: A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.
A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a manipulation of the argument additional_args/target/username/password/scan_type/payload can lead to os command injecti
nvd
CVE-2026-90691P3HIGHCVSS 8.3vd689933ff579d839c676c82b231f8e98326c5f042026-09-14
CVE-2026-90691 [HIGH] CWE-22 CVE-2026-90691: A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8
A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is the function FileOperationsManager of the file hexstrike_server.py of the component API Files Endpoint. The manipulation of the argument filename leads to path traversal. The attack may be initiated remotely. The expl
nvd
CVE-2026-90620P3HIGHCVSS 7.3vd689933ff579d839c676c82b231f8e98326c5f042026-09-14
CVE-2026-90620 [HIGH] CWE-287 CVE-2026-90620: A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.
A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been publicly disclosed and may be
nvd