Description
A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is the function FileOperationsManager of the file hexstrike_server.py of the component API Files Endpoint. The manipulation of the argument filename leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Access
Action: Patch Immediately
AI Analysis

Impact

The flaw is a classic path traversal bug situated in the FileOperationsManager function of the hexstrike_server.py component of the HexStrike AI API Files Endpoint. By manipulating the filename argument, system directories outside the intended file boundary, potentially allowing them to read arbitrary files on the host. The attack can be initiated remotely and the vulnerability has been publicly disclosed, meaning that no special privilege escalation is required if the API is exposed.

Affected Systems

This weakness affects the HexStrike AI product developed by 0x4m4. It is present in all releases up to the commit identified as d689933ff579d839c676c82b231f8e98326c5f04. The references point to the open‑source code repository, and the CPE string confirms that the vulnerable component is part of the HexStrike AI application.

Risk and Exploitability

The CVSS score of 6.9 places the vulnerability in the medium severity range, and the EPSS score of < 1% suggests a low current exploitation likelihood. Although the vulnerability is publicly disclosed and the source code is open source, it remains unpatched, indicating that it is an active threat. The flaw can be exploited remotely via the API's filename parameter, allowing an attacker to read arbitrary files on the host, but no privilege escalation beyond the normal API credentials is required.

Generated by OpenCVE AI on September 15, 2026 at 15:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the fix from pull request 159 or upgrade the application to a commit that includes the path traversal patch
  • Sanitize the filename argument in the API by rejecting any ".." sequences and enforcing a whitelist of allowed directories
  • Restrict API access to authenticated users and apply network segmentation or firewall rules to limit exposure to trusted networks

Generated by OpenCVE AI on September 15, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is the function FileOperationsManager of the file hexstrike_server.py of the component API Files Endpoint. The manipulation of the argument filename leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title 0x4m4 HexStrike AI API Files Endpoint hexstrike_server.py FileOperationsManager path traversal
First Time appeared 0x4m4
0x4m4 hexstrike Ai
Weaknesses CWE-22
CPEs cpe:2.3:a:0x4m4:hexstrike_ai:*:*:*:*:*:*:*:*
Vendors & Products 0x4m4
0x4m4 hexstrike Ai
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 8.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

0x4m4 Hexstrike Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T16:26:12.061Z

Reserved: 2026-09-13T05:07:51.671Z

Link: CVE-2026-90691

cve-icon Vulnrichment

Updated: 2026-09-14T16:26:03.333Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:25.080

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')