Executive brief
Strix, an autonomous AI-based penetration testing tool, contains a design flaw that allows it to be tricked into installing malicious software. By presenting the AI agent with a fake error message that suggests installing a specific package, an attacker can gain remote control over the machine running the Strix software. This effectively turns the security testing tool against its operator, potentially leading to a full breach of the pentester's environment.
Technical details
The vulnerability stems from two primary design defects in the Strix autonomous agent framework. First, the 'system_prompt.jinja' file contains an unrestricted policy (CWE-829) that explicitly permits agents to install arbitrary packages via pip, apt, or npm without provenance verification. Second, the multi-agent architecture fails to propagate safety boundaries; child agents do not consult security notes created by the root agent. An attacker can exploit this by hosting a target application that returns a crafted error message (Indirect Prompt Injection). The Strix agent, following its instructions to exhaustively probe and remediate errors, will execute a 'pip install' from an attacker-controlled mirror, leading to a reverse shell via malicious code in the package's setup files. As of the advisory date, the vendor has not responded to disclosure attempts.
Affected products
- usestrix strix up to 1.0.2
Timeline
- 2026-07-12: disclosed: Vulnerability reported via GitHub and VulDB.
- 2026-07-13: advisory: NVD published CVE-2026-15519.