Skip to content

Add 3 critical security advisories for hexstrike-ai (0x4m4/hexstrike-ai)#7442

Closed
sermikr0 wants to merge 1 commit into
github:sermikr0/advisory-improvement-7442from
sermikr0:hexstrike-ai-critical-vulns
Closed

Add 3 critical security advisories for hexstrike-ai (0x4m4/hexstrike-ai)#7442
sermikr0 wants to merge 1 commit into
github:sermikr0/advisory-improvement-7442from
sermikr0:hexstrike-ai-critical-vulns

Conversation

@sermikr0
Copy link
Copy Markdown

Summary

This PR adds 3 critical security advisories for hexstrike-ai (8,200+ stars), an AI-powered cybersecurity toolkit.

All vulnerabilities confirmed with local PoC testing, present in latest version.

Advisories

ID Vulnerability CVSS CWE
GHSA-h3x5-r9c2-qm47 Unauthenticated RCE via /api/command 9.8 CWE-78, CWE-306
GHSA-v7p8-c4f6-jw32 Command Injection in /api/tools/* 9.8 CWE-78
GHSA-w2k9-m5g4-xr86 Path Traversal in /api/files/* 9.8 CWE-22, CWE-306

Details

- GHSA-h3x5-r9c2-qm47: Unauthenticated RCE via /api/command (CVSS 9.8)
- GHSA-v7p8-c4f6-jw32: Command Injection in /api/tools/* endpoints (CVSS 9.8)
- GHSA-w2k9-m5g4-xr86: Path Traversal in /api/files/* endpoints (CVSS 9.8)

All vulnerabilities confirmed with local PoC testing.
@github-actions github-actions Bot changed the base branch from main to sermikr0/advisory-improvement-7442 April 20, 2026 00:14
@taladrane
Copy link
Copy Markdown
Collaborator

👋 github/advisory-database is not a venue for disclosing new vulnerabilities, publishing proof‑of‑concepts, or coordinating a report when a vendor is unresponsive. This repository’s purpose is to curate and publish advisory records (e.g., for already-tracked, publicly referenceable vulnerabilities) so ecosystems and tooling can consume consistent metadata. To ensure your report is appropriately handled, please refer to Privately reporting a security vulnerability, which includes instructions for repositories that don't have private vulnerability reporting enabled.

Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@taladrane taladrane closed this Apr 24, 2026
@sermikr0 sermikr0 deleted the hexstrike-ai-critical-vulns branch April 24, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants