Executive brief
HexStrike AI is an AI-powered security analysis tool with a file handling API endpoint. A path traversal vulnerability in the file operations functionality allows remote attackers to write arbitrary files outside the intended sandbox directory, potentially enabling remote code execution by injecting malicious scripts (e.g., web shells) into system-accessible locations.
Technical details
The vulnerability is a path traversal (CWE-22) in the FileOperationsManager component of hexstrike_server.py, specifically in the API Files Endpoint. The vulnerable code fails to validate the filename parameter before combining it with a base directory, allowing attackers to use sequences like "../../../" to escape the sandbox. The vulnerability affects file creation and modification endpoints (/api/files/create and /api/files/modify). An unauthenticated remote attacker can exploit this to write arbitrary files to any location on the system (e.g., /var/www/html/shell.php for RCE or SSH keys for account takeover). The issue has been publicly disclosed but no patch has been released as the project maintainers have not responded.
Affected products
- 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04
Timeline
- 2026-01-18: disclosed: Security issue reported via GitHub issue #135
- 2026-09-14: disclosed: CVE-2026-90691 published
- 2026-09-14: other: Public disclosure; project has not responded to maintainers