在 0x4m4 HexStrike AI 中检测到一个安全漏洞,受影响版本范围为 d689933ff579d839c676c82b231f8e98326c5f04 及之前版本。受影响的组件是 API 文件端点中 文件里 函数。对参数 的操作可导致路径遍历漏洞。该攻击可远程发起。此漏洞的利用方法已公开披露,可能存在被利用的风险。项目方通过问题报告较早地获知了该问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 0x4m4 | HexStrike AI | d689933ff579d839c676c82b231f8e98326c5f04 |
cpe:2.3:a:0x4m4:hexstrike_ai:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90619 | 7.3 HIGH | 0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injection |
| CVE-2026-90620 | 7.3 HIGH | 0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authentication |
| CVE-2026-90690 | 7.3 HIGH | 0x4m4 HexStrike AI API Tools Endpoint hexstrike_server.py subprocess.Popen os command inje |
No comments yet