Description
A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code/script leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: 2.1% Low
KEV: No
Impact: Remote OS Command Injection
Action: Restrict Access
AI Analysis

Impact

The flaw is an operating system command injection in the Execute Endpoint of HexStrike AI's server component. By supplying a crafted value for the code/script argument, an attacker can cause the backend to execute arbitrary shell commands on the host. This gives the attacker full control over the underlying system, compromising confidentiality, integrity, and availability. The vulnerability is remote, as the server accepts network requests to the endpoint.

Affected Systems

The affected product is 0x4m4 HexStrike AI. Affected code resides in hexstrike_server.py, part of the Execute Endpoint. Because the project uses a rolling release model, no specific version identifiers are listed; all releases that incorporate code prior to the commit d689933ff579d839c676c82b231f8e98326c5f04 are vulnerable until a fix is deployed.

Risk and Exploitability

The CVSS base score of 6.9 indicates a medium risk severity. EPSS is 1%, indicating that while the probability of exploitation is low, it is not, suggesting that exploitation may be possible. The vulnerability is listed as not included in the CISA KEV catalog. Attackers with network access to the Execute Endpoint can send malicious input and trigger shell execution. No patch or workaround is currently available from the vendor.

Generated by OpenCVE AI on September 15, 2026 at 15:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict network access to the Execute Endpoint, blocking or limiting IPs that can reach it.
  • Deploy the latest upstream code once the project issues an attempts and monitor for anomalous activity.
  • If a patch is not available, consider disabling the Execute Endpoint feature until it is resolved or move the service behind an additional authentication layer.

Generated by OpenCVE AI on September 15, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code/script leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title 0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injection
First Time appeared 0x4m4
0x4m4 hexstrike Ai
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:0x4m4:hexstrike_ai:*:*:*:*:*:*:*:*
Vendors & Products 0x4m4
0x4m4 hexstrike Ai
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

0x4m4 Hexstrike Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:42:09.786Z

Reserved: 2026-09-12T20:11:27.004Z

Link: CVE-2026-90619

cve-icon Vulnrichment

Updated: 2026-09-16T14:41:58.172Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T03:16:37.427

Modified: 2026-09-16T15:18:35.040

Link: CVE-2026-90619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:46:46Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')