Add 3 critical security advisories for hexstrike-ai (0x4m4/hexstrike-ai)#7442
Conversation
- GHSA-h3x5-r9c2-qm47: Unauthenticated RCE via /api/command (CVSS 9.8) - GHSA-v7p8-c4f6-jw32: Command Injection in /api/tools/* endpoints (CVSS 9.8) - GHSA-w2k9-m5g4-xr86: Path Traversal in /api/files/* endpoints (CVSS 9.8) All vulnerabilities confirmed with local PoC testing.
|
👋 Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
Summary
This PR adds 3 critical security advisories for hexstrike-ai (8,200+ stars), an AI-powered cybersecurity toolkit.
All vulnerabilities confirmed with local PoC testing, present in latest version.
Advisories
/api/command/api/tools/*/api/files/*Details
hexstrike_server.py