HIGH 8.6
PYSEC-2026-500
pymetasploit3 vulnerable to command injection in console.run_module_with_output()
상세
Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended command structure and causes the Metasploit console to execute additional unintended commands, potentially leading to arbitrary command execution and manipulation of Metasploit sessions.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
PyPI / pymetasploit3
최초 영향 버전:
0 No fixed version published yet for pymetasploit3 (pip). Pin to a known-safe version or switch to an alternative.