OS Command Injection Vulnerability in 0x4m4 HexStrike AI API Tools Endpoint
CVE-2026-90690
Key Information:
- Vendor
0x4m4
- Status
- Vendor
- CVE Published:
- 14 September 2026
Badges
What is CVE-2026-90690?
A vulnerability exists in the 0x4m4 HexStrike AI API Tools Endpoint due to improper handling of arguments within the subprocess.Popen function in hexstrike_server.py. Attackers can exploit this weakness to execute arbitrary OS commands remotely by manipulating various input parameters such as additional_args, target, username, password, scan_type, and payload. The exploit is publicly available, making it crucial for users to be aware and take preventive measures. The vendor is actively working on a patch to address this vulnerability.
Affected Version(s)
HexStrike AI d689933ff579d839c676c82b231f8e98326c5f04
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
