Impact
The flaw is a classic path traversal bug situated in the FileOperationsManager function of the hexstrike_server.py component of the HexStrike AI API Files Endpoint. By manipulating the filename argument, system directories outside the intended file boundary, potentially allowing them to read arbitrary files on the host. The attack can be initiated remotely and the vulnerability has been publicly disclosed, meaning that no special privilege escalation is required if the API is exposed.
Affected Systems
This weakness affects the HexStrike AI product developed by 0x4m4. It is present in all releases up to the commit identified as d689933ff579d839c676c82b231f8e98326c5f04. The references point to the open‑source code repository, and the CPE string confirms that the vulnerable component is part of the HexStrike AI application.
Risk and Exploitability
The CVSS score of 6.9 places the vulnerability in the medium severity range, and the EPSS score of < 1% suggests a low current exploitation likelihood. Although the vulnerability is publicly disclosed and the source code is open source, it remains unpatched, indicating that it is an active threat. The flaw can be exploited remotely via the API's filename parameter, allowing an attacker to read arbitrary files on the host, but no privilege escalation beyond the normal API credentials is required.
OpenCVE Enrichment