CVE-2025-35028 CRITICAL

CVE-2025-35028: HexStrike AI MCP Server Command Injection

Vendor 0X4M4
Product HexStrike AI
Weakness CWE-78
Published November 30, 2025
Last update December 1, 2025

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the default configuration of this MCP server at the affected version (as of commit 2f3a5512 in September of 2025).

Key dates

02Disclosure timeline

November 30, 2025 CVE published
December 1, 2025 Record updated