CVE-2026-5463Disclosure(danmcinerney / pymetasploit3)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (5 latest mentions)

Immediate actions

  • Prioritize remediation for danmcinerney pymetasploit3 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended command structure and causes the Metasploit console to execute additional unintended commands, potentially leading to arbitrary command execution and manipulation of Metasploit sessions.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pymetasploit3

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • 5 total mentions across 1 day

Affected systems

Products
pymetasploit3

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-04-03: 5PoC Mentioned / Linked · 2026-04-03: 1Exploit Tool / Code · 2026-04-03: 2Technical Details · 2026-04-03: 504-03
Signal classification2 categories
Disclosure
360.0%
Exploit
240.0%
Referenced assets6 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5463 Command injection vulnerability in http://console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module opt… https://www.cve.org/CVERecord?id=CVE-2026-5463

    Post summary

    CVE-2026-5463 reveals a command injection flaw in pymetasploit3, allowing newline-based injection through console.run_module_with_output().

    0000078
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Exploit

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5463 - Metasploit Command Injection Intel Report: https://ift.tt/sgLXDMw

    Post summary

    The post announces the CVE‑2026‑5463 vulnerability with a Metasploit command‑injection exploit, but offers no details on patches or active exploitation.

    0000041
    281 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-5463 - High Command injection vulnerability in http://console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. Thi... https://www.thehackerwire.com/vulnerability/CVE-2026-5463/ https://t.co/KlfWf0vvz1

    Post summary

    The post discloses a high‑severity command injection vulnerability (CVE-2026-5463) in pymetasploit3 that permits newline injection into options like RHOSTS, but it offers no PoC, exploit code, or remediation details.

    0000049
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5463: CRITICAL] Beware of command injection vulnerability in pymetasploit3 http://console.run_module_with_output() up to v1.0.6, enabling attackers to execute unintended commands. #cybersecurity#cve,CVE-2026-5463,#cybersecurity https://cvefind.com/CVE-2026-5463

    Post summary

    The post alerts to a critical command‑injection flaw in PyMeteSploit3’s console.run_module_with_output() that could allow arbitrary command execution, but no details on patches, PoCs, or active exploitation are given.

    0000047
    617 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-5463: Dan McInerney (CVSS: 9.3)... Newline injection in pymetasploit3's RHOSTS parameter breaks command parsing—attackers can chain arbitrary MSF commands ... https://zerodaysignal.com/vulnerability/CVE-2026-5463 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a high‑severity CVE-2026-5463 that allows newline injection in pymetasploit3’s RHOSTS parameter, enabling arbitrary Metasploit command execution—PoC and exploit details are available online.

    0000067
    193 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdanmcinerneypymetasploit3---

Explore more