CVE-2026-90690: OS Command Injection in 0x4m4 HexStrike AI
A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a manipulation of the argument additional_args/target/username/password/scan_type/payload can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. A fix appears to be in progress.
AI Analysis
Technical Summary
This vulnerability exists in the API Tools Endpoint component of 0x4m4 HexStrike AI, specifically in the subprocess.Popen function within hexstrike_server.py. An attacker can remotely exploit this by manipulating the arguments additional_args, target, username, password, scan_type, or payload to inject OS commands. The product lacks versioning, so no specific affected versions are identified. A patch or official fix is not yet available but is in progress. Exploit code has been publicly released, but no known exploitation in the wild has been reported.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary OS commands on the affected system, potentially leading to system compromise. The vulnerability is remotely exploitable without authentication and requires low attack complexity. The overall impact is rated medium based on the CVSS 4.0 vector.
Mitigation Recommendations
A fix is currently in progress; no official patch is available at this time. Users should monitor vendor advisories for updates and apply the official fix once released. Until then, consider restricting access to the vulnerable API endpoint to trusted networks or users to reduce exposure.
CVE-2026-90690: OS Command Injection in 0x4m4 HexStrike AI
Description
A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a manipulation of the argument additional_args/target/username/password/scan_type/payload can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. A fix appears to be in progress.
CVSS v4.0
Score 6.9medium
Affected software
0x4m4
HexStrike AI
cpe:2.3:a:0x4m4:hexstrike_ai:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in the API Tools Endpoint component of 0x4m4 HexStrike AI, specifically in the subprocess.Popen function within hexstrike_server.py. An attacker can remotely exploit this by manipulating the arguments additional_args, target, username, password, scan_type, or payload to inject OS commands. The product lacks versioning, so no specific affected versions are identified. A patch or official fix is not yet available but is in progress. Exploit code has been publicly released, but no known exploitation in the wild has been reported.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary OS commands on the affected system, potentially leading to system compromise. The vulnerability is remotely exploitable without authentication and requires low attack complexity. The overall impact is rated medium based on the CVSS 4.0 vector.
Mitigation Recommendations
A fix is currently in progress; no official patch is available at this time. Users should monitor vendor advisories for updates and apply the official fix once released. Until then, consider restricting access to the vulnerable API endpoint to trusted networks or users to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-13T05:07:48.304Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa79c0455bf5e2cf5ac9da5
Added to database: 09/14/2026, 07:02:28 UTC
Last enriched: 09/14/2026, 07:17:26 UTC
Last updated: 09/15/2026, 03:38:36 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.