GHSA-qpc3-8vqg-8g6w · Severity: critical · Ecosystem: pip — pymetasploit3 vulnerable to command injection in console.run_module_with_output()
Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended command structure and causes the Metasploit console to execute additional unintended commands, potentially leading to arbitrary command execution and manipulation of Metasploit sessions.
Conclusion & alert: CVE-2026-5463 is rated Moderate Risk (55.2/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.32%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-03 | 1.74% | 0.32% | -1.42% |
| 2 | 2026-05-05 | 1.78% | 1.74% | -0.05% |
| 3 | 2026-04-09 | — | 1.78% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 4.0 | CRITICAL |
|
— | — | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c |
| 8.6 | 3.1 | HIGH |
|
3.9 | 4.7 | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c |
GHSA-qpc3-8vqg-8g6w · Severity: critical · Ecosystem: pip — pymetasploit3 vulnerable to command injection in console.run_module_with_output()
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| danmcinerney | pymetasploit3 | <= 1.0.6 | cpe:2.3:a:danmcinerney:pymetasploit3:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/DanMcInerney/pymetasploit3 | Product |
| https://pypi.org/project/pymetasploit3/ | Product |