Executive brief
HexStrike AI is an open-source security testing tool that provides a suite of hacking and penetration testing utilities via a web API. A command injection vulnerability in over 90 API endpoints allows remote attackers to execute arbitrary operating system commands by manipulating input parameters such as additional_args, target, username, password, scan_type, and payload. An attacker can exploit this to gain full system control and potentially compromise the security infrastructure relying on this tool.
Technical details
The vulnerability is a classic OS command injection flaw in the subprocess.Popen call within hexstrike_server.py's API Tools Endpoint. The vulnerable component fails to properly sanitize or escape user-supplied arguments (additional_args, target, username, password, scan_type, payload) before passing them to subprocess.Popen, allowing attackers to break out of intended command syntax and inject arbitrary shell commands. The attack is network-reachable with no authentication required. A successful exploit results in remote code execution with the privileges of the application process. A fix is in progress via pull request #266 on the GitHub repository.
Affected products
- 0x4m4 HexStrike AI up to commit d689933ff579d839c676c82b231f8e98326c5f04
Timeline
- 2026-09-14: disclosed: CVE-2026-90690 published
- 2026-09-09: other: Fix pull request #266 submitted