PT-2025-48397 · Unknown · Hexstrike Ai Mcp Server
Jippen
+1
·
Published
2025-11-30
·
Updated
2025-12-05
·
CVE-2025-35028
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
HexStrike AI MCP Server versions prior to commit 2f3a5512
Description
The HexStrike AI MCP Server is susceptible to a command injection issue. By supplying a command-line argument beginning with a semicolon (
;) to an API endpoint created by the EnhancedCommandExecutor class, a composed command is directly executed with root privileges. The server does not sanitize these arguments in its default configuration. The EnhancedCommandExecutor class is the component responsible for processing commands. The username and password parameters are not explicitly mentioned as being involved in this issue.Recommendations
Versions prior to commit 2f3a5512 should be updated to a version containing the fix. As a temporary workaround, consider disabling the
EnhancedCommandExecutor class or restricting access to the affected API endpoint until a patch is available.Exploit
Fix
LPE
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hexstrike Ai Mcp Server