Impact
The vulnerability arises in the API Tools Endpoint module of 0x4m4 HexStrike AI, where user-controlled arguments such as target, are passed directly to subprocess.Popen without proper sanitization. This flaw allows an attacker to inject arbitrary shell commands, leading to remote code execution on the host running the service. The consequence is loss of confidentiality, integrity, and availability, and the attacker could achieve full system compromise. The weakness is classified under CWE-77 and CWE-78, representing command injection vulnerabilities.
Affected Systems
0x4m4 HexStrike AI’s HexStrike AI product has no versioning scheme, so all releases up to commit d689933ff579d839c676c82b231f8e98326c5f04 are potentially affected. No statements about unaffected releases exist because version data is unavailable. The affected component is the hexstrike_server.py file residing in the API Tools Endpoint directory.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate to high severity. Although the EPSS score is 1%, the public availability of an exploit and the remote nature of the attack vector strongly suggest a non-negligible risk of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers only need to send crafted requests to the exposed API endpoint; no local access or privilege escalation is required. This ease of exploitation makes the flaw a priority for remediation.
OpenCVE Enrichment