Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpc3-8vqg-8g6w

Опубликовано: 03 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 8.6

Описание

pymetasploit3 vulnerable to command injection in console.run_module_with_output()

Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended command structure and causes the Metasploit console to execute additional unintended commands, potentially leading to arbitrary command execution and manipulation of Metasploit sessions.

Пакеты

Наименование

pymetasploit3

pip
Затронутые версииВерсия исправления

<= 1.0.6

Отсутствует

EPSS

Процентиль: 78%
0.01068
Низкий

9.3 Critical

CVSS4

8.6 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.6
nvd
4 дня назад

Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended command structure and causes the Metasploit console to execute additional unintended commands, potentially leading to arbitrary command execution and manipulation of Metasploit sessions.

EPSS

Процентиль: 78%
0.01068
Низкий

9.3 Critical

CVSS4

8.6 High

CVSS3

Дефекты

CWE-77