在 0x4m4 HexStrike AI 的一个版本(截至提交 )中发现了一个弱点。受影响的组件是 API Tools 端点中的 文件里的 函数。通过对参数 、 、 、 或 、 进行操纵,可导致 操作系统命令注入(OS command injection)。该攻击可远程发起。利用该漏洞的公开 PoC(Proof of Concept)已可供公众使用,可用于实际攻击。该产品不使用版本号进行版本管理,因此无法提供受影响与未受影响版本的具体信息。目前修复工作正在进行中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 0x4m4 | HexStrike AI | d689933ff579d839c676c82b231f8e98326c5f04 |
cpe:2.3:a:0x4m4:hexstrike_ai:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90691 | 8.3 HIGH | 0x4m4 HexStrike AI API Files Endpoint hexstrike_server.py FileOperationsManager path trave |
| CVE-2026-90619 | 7.3 HIGH | 0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injection |
| CVE-2026-90620 | 7.3 HIGH | 0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authentication |
No comments yet