CVE 9.3 CRITICAL

CVE-2026-5463_CVE-2026-5463

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L

Description

Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended command structure and causes the Metasploit console to execute additional unintended commands, potentially leading to arbitrary command execution and manipulation of Metasploit sessions.

Basic Information

ID CVE-2026-5463
Source TuranSec
Published Apr 3, 2026 at 04:32
Modified Apr 3, 2026 at 15:35

Affected Product

Vendor Dan McInerney
Product pymetasploit3
Affected Versions Dan McInerney pymetasploit3 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.