Skip to content
Sebastion AI security score

0x4m4/hexstrike-ai

B
Last audited
6 May 2026
Lines scanned
1,284,902
PRs merged
11
2
Critical
7
High
19
Medium
34
Low
CWE breakdown

What we found, by category.

CWE-79

Cross-site scripting in HTML output

14
CWE-89

SQL injection through unsanitised query construction

3
CWE-22

Path traversal in file system access

8
CWE-918

Server-side request forgery to internal services

6
CWE-78

OS command injection through unescaped arguments

2
CWE-352

Cross-site request forgery on state-changing endpoints

5
Recent findings

Filed and tracked.

CriticalCWE-918Fixed

Server-side request forgery in image optimisation loader

CriticalCWE-22Open

Path traversal via unvalidated route segment in static export

HighCWE-79Fixed

Reflected XSS in dev overlay error frame renderer

HighCWE-352Open

CSRF token not validated on server action revalidation endpoint

HighCWE-78Won't fix

Command injection through user-supplied build env in turbo runner

MediumCWE-79Fixed

DOM XSS via unsanitised hash fragment in router fallback

MediumCWE-89Open

SQL injection in example app data adapter

Embed

Show the audit on your README.

Audited by Foundation Machines · 0x4m4/hexstrike-aiDrop this in your README to show the audit.
[![Audited by Foundation Machines](https://foundationmachines.ai/badge/0x4m4/hexstrike-ai.svg)](https://foundationmachines.ai/scores/0x4m4/hexstrike-ai)
Methodology

How we score.

Every commit is run through static analysis, dynamic fuzzing in an ephemeral microVM and an LLM-assisted review tuned for the AI stack. Three lenses on the same code.

We trace data flow from sources like request bodies, env vars and uploaded files all the way to sinks like SQL clients, shell invocations and outbound HTTP. No taint, no finding.

Nothing is reported without a working proof-of-concept test that triggers the vulnerability. Findings ship with a draft PR you can merge, not a backlog you have to triage.

Get this score for your repo.

Install Sebastion AI on GitHub and get a security score for every PR.