Description
A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a manipulation of the argument additional_args/target/username/password/scan_type/payload can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. A fix appears to be in progress.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: 2.1% Low
KEV: No
Impact: Remote command execution via OS command injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises in the API Tools Endpoint module of 0x4m4 HexStrike AI, where user-controlled arguments such as target, are passed directly to subprocess.Popen without proper sanitization. This flaw allows an attacker to inject arbitrary shell commands, leading to remote code execution on the host running the service. The consequence is loss of confidentiality, integrity, and availability, and the attacker could achieve full system compromise. The weakness is classified under CWE-77 and CWE-78, representing command injection vulnerabilities.

Affected Systems

0x4m4 HexStrike AI’s HexStrike AI product has no versioning scheme, so all releases up to commit d689933ff579d839c676c82b231f8e98326c5f04 are potentially affected. No statements about unaffected releases exist because version data is unavailable. The affected component is the hexstrike_server.py file residing in the API Tools Endpoint directory.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate to high severity. Although the EPSS score is 1%, the public availability of an exploit and the remote nature of the attack vector strongly suggest a non-negligible risk of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers only need to send crafted requests to the exposed API endpoint; no local access or privilege escalation is required. This ease of exploitation makes the flaw a priority for remediation.

Generated by OpenCVE AI on September 15, 2026 at 15:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the upcoming patch from 0x4m4 that sanitizes all arguments passed to subprocess.Popen and replaces unsafe shell calls with safe subprocess invocation methods.
  • Enforce strict authentication and authorization for the API Tools Endpoint, limiting access to trusted users only.
  • Validate and sanitize all user-supplied parameters (target, username, password, scan_type, payload) on the server side to eliminate the possibility of shell injection.

Generated by OpenCVE AI on September 15, 2026 at 15:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a manipulation of the argument additional_args/target/username/password/scan_type/payload can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. A fix appears to be in progress.
Title 0x4m4 HexStrike AI API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection
First Time appeared 0x4m4
0x4m4 hexstrike Ai
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:0x4m4:hexstrike_ai:*:*:*:*:*:*:*:*
Vendors & Products 0x4m4
0x4m4 hexstrike Ai
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

0x4m4 Hexstrike Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:46:09.190Z

Reserved: 2026-09-13T05:07:48.304Z

Link: CVE-2026-90690

cve-icon Vulnrichment

Updated: 2026-09-16T14:46:02.778Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:24.880

Modified: 2026-09-16T15:18:39.120

Link: CVE-2026-90690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:15:15Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')