Impact
A missing authentication check in the hexstrike_server.py file allows remote actors to invoke an unknown API command endpoint without credentials, enabling unauthorized command execution. The flaw resides in an unproven function of the file that is exposed through the component’s API, and the attack can be launched from outside the network.
Affected Systems
The vulnerability affects 0x4m4’s HexStrike AI product. No specific version numbers are provided in the advisory because the project uses continuous delivery with rolling releases; the issue applies to all releases up to the commit d689933ff579d839c676c82b231f8e98326c5f04.
Risk and Exploitability
The CVSS score is 6.9, indicating a medium severity vulnerability. EPSS score is <1%, indicating a very low probability of exploitation, and the issue is not listed in CISA’s KEV catalog. Because the flaw permits unauthenticated access to the command endpoint, remote exploitation is straightforward for an attacker who can reach the service over the network.
OpenCVE Enrichment