Junglewise Threat Intelligence

CVE-2026-90690: 0x4m4 HexStrike AI command injection in API Tools Endpoint

CVE-2026-90690 · Severity: high · CVSS 7.3 · Published 2026-09-14

Technologies: 0x4m4 HexStrike AI. Vendors: 0x4m4.

Executive brief

HexStrike AI is an open-source security testing tool that provides a suite of hacking and penetration testing utilities via a web API. A command injection vulnerability in over 90 API endpoints allows remote attackers to execute arbitrary operating system commands by manipulating input parameters such as additional_args, target, username, password, scan_type, and payload. An attacker can exploit this to gain full system control and potentially compromise the security infrastructure relying on this tool.

Technical details

The vulnerability is a classic OS command injection flaw in the subprocess.Popen call within hexstrike_server.py's API Tools Endpoint. The vulnerable component fails to properly sanitize or escape user-supplied arguments (additional_args, target, username, password, scan_type, payload) before passing them to subprocess.Popen, allowing attackers to break out of intended command syntax and inject arbitrary shell commands. The attack is network-reachable with no authentication required. A successful exploit results in remote code execution with the privileges of the application process. A fix is in progress via pull request #266 on the GitHub repository.

Affected products

  • 0x4m4 HexStrike AI up to commit d689933ff579d839c676c82b231f8e98326c5f04

Timeline

  • 2026-09-14: disclosed: CVE-2026-90690 published
  • 2026-09-09: other: Fix pull request #266 submitted

References

Related threats