9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP serverβs normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the default configuration of this MCP server at the affected version (as of commit 2f3a5512 in September of 2025).
AI Analysis
Command injection vulnerability in HexStrike AI MCP server via unsanitized command-line arguments
Basic Information
ID
CVE-2025-35028
Source
AHA
Published
Nov 30, 2025 at 21:27
Modified
Nov 30, 2025 at 22:03
Affected Product
Vendor
0x4m4
Product
HexStrike AI
Version
33267047667b9accfbf0fdac1c1c7ff12f3a5512
Affected Versions
0x4m4 HexStrike AI 33267047667b9accfbf0fdac1c1c7ff12f3a5512
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
0x4m4
Product
HexStrike AI MCP Server
Version
33267047667b9accfbf0fdac1c1c7ff12f3a5512