PT-2026-29988 · Unknown · Pymetasploit3

·

CVE-2026-5463

·

Published

2026-04-03

·

Updated

2026-06-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pymetasploit3 versions through 1.0.6
Description A command injection issue exists in the console.run module with output() function of pymetasploit3. Attackers can inject newline characters into module options, such as the RHOSTS parameter, disrupting command parsing and potentially enabling arbitrary command execution and manipulation of Metasploit sessions.
Recommendations Update pymetasploit3 to a version later than 1.0.6.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5463
GHSA-QPC3-8VQG-8G6W
PYSEC-2026-500

Affected Products

Pymetasploit3