PT-2026-29988 · Unknown · Pymetasploit3

Abdivasiyev Sunnatillo

·

Published

2026-04-03

·

Updated

2026-04-03

·

CVE-2026-5463

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pymetasploit3 versions through 1.0.6
Description A command injection issue exists in the console.run module with output() function of pymetasploit3. Attackers can inject newline characters into module options, such as the RHOSTS parameter, disrupting command parsing and potentially enabling arbitrary command execution and manipulation of Metasploit sessions.
Recommendations Update pymetasploit3 to a version later than 1.0.6.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5463
GHSA-QPC3-8VQG-8G6W

Affected Products

Pymetasploit3