criticalCVSS 8.6Vulnerability

CVE-2026-5463

Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended command structure and causes the Metasploit console to execute additional unintended commands, potentially leading to arbitrary command execution and manipulation of Metasploit sessions.

Properties

severity
critical
summary
pymetasploit3 vulnerable to command injection in console.run_module_with_output()
epss_score
0.01923
cvss_score
8.6
ghsa_published
2026-04-03T06:31:33Z
source_url
https://github.com/advisories/GHSA-qpc3-8vqg-8g6w
ghsa_updated
2026-04-06T23:07:59Z
ghsa_id
GHSA-qpc3-8vqg-8g6w
cve_id
CVE-2026-5463
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
is_ghsa_only
false
epss_percentile
0.78361

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS (1)

[Software]pip/pymetasploit3

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph