Impact
The flaw is an operating system command injection in the Execute Endpoint of HexStrike AI's server component. By supplying a crafted value for the code/script argument, an attacker can cause the backend to execute arbitrary shell commands on the host. This gives the attacker full control over the underlying system, compromising confidentiality, integrity, and availability. The vulnerability is remote, as the server accepts network requests to the endpoint.
Affected Systems
The affected product is 0x4m4 HexStrike AI. Affected code resides in hexstrike_server.py, part of the Execute Endpoint. Because the project uses a rolling release model, no specific version identifiers are listed; all releases that incorporate code prior to the commit d689933ff579d839c676c82b231f8e98326c5f04 are vulnerable until a fix is deployed.
Risk and Exploitability
The CVSS base score of 6.9 indicates a medium risk severity. EPSS is 1%, indicating that while the probability of exploitation is low, it is not, suggesting that exploitation may be possible. The vulnerability is listed as not included in the CISA KEV catalog. Attackers with network access to the Execute Endpoint can send malicious input and trigger shell execution. No patch or workaround is currently available from the vendor.
OpenCVE Enrichment