Junglewise Threat Intelligence

CVE-2026-15519: usestrix strix remote code execution via indirect prompt injection

CVE-2026-15519 · Severity: medium · CVSS 5 · Published 2026-07-13

Executive brief

Strix, an autonomous AI-based penetration testing tool, contains a design flaw that allows it to be tricked into installing malicious software. By presenting the AI agent with a fake error message that suggests installing a specific package, an attacker can gain remote control over the machine running the Strix software. This effectively turns the security testing tool against its operator, potentially leading to a full breach of the pentester's environment.

Technical details

The vulnerability stems from two primary design defects in the Strix autonomous agent framework. First, the 'system_prompt.jinja' file contains an unrestricted policy (CWE-829) that explicitly permits agents to install arbitrary packages via pip, apt, or npm without provenance verification. Second, the multi-agent architecture fails to propagate safety boundaries; child agents do not consult security notes created by the root agent. An attacker can exploit this by hosting a target application that returns a crafted error message (Indirect Prompt Injection). The Strix agent, following its instructions to exhaustively probe and remediate errors, will execute a 'pip install' from an attacker-controlled mirror, leading to a reverse shell via malicious code in the package's setup files. As of the advisory date, the vendor has not responded to disclosure attempts.

Affected products

  • usestrix strix up to 1.0.2

Timeline

  • 2026-07-12: disclosed: Vulnerability reported via GitHub and VulDB.
  • 2026-07-13: advisory: NVD published CVE-2026-15519.

References