CVE-2025-35028: critical vulnerability in 0x4m4 HexStrike AI
HexStrike AI MCP Server Command Injection
Published · Updated
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.1epss 5.3%
exploitation probability
5.3%top 8% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the default configuration of this MCP server at the affected version (as of commit 2f3a5512 in September of 2025).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
0x4m4 · HexStrike AIpublic PoCs found — 1
cve_referencetakeonme.org/gcves/GCVE-1337-2025-00000000000000000000000000000000000000000000000000111111111111111111111111000000000000000000000000000000000000000000000000000000011unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — 0x4m4 HexStrike AI
In the same product, most dangerous first.
CVE-2026-90690MEDIUM0x4m4 HexStrike AI API Tools Endpoint hexstrike_server.py subprocess.Popen os command injectionEPSS 2.1%CVE-2026-90619MEDIUM0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injectionEPSS 2.1%CVE-2026-90620MEDIUM0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authenticationEPSS 0.7%CVE-2026-90691MEDIUM0x4m4 HexStrike AI API Files Endpoint hexstrike_server.py FileOperationsManager path traversalEPSS 0.6%