
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5463 is a command injection vulnerability in the console.run_module_with_output() function of pymetasploit3, a Python3 automation library for Metasploit. Attackers can inject newline characters into module options such as RHOSTS, breaking the intended command structure and causing the Metasploit console to execute additional unintended commands. All versions through 1.0.6 are affected. The vulnerability was published on April 3, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (Github Advisory, Feedly).
The root cause is improper neutralization of special elements used in a command (CWE-77). The console.run_module_with_output() function passes user-supplied module option values — such as RHOSTS — directly to the Metasploit console without sanitizing newline characters (\n). Because the Metasploit console interprets newlines as command delimiters, an attacker who can influence module option values can inject arbitrary additional console commands into the command stream. No authentication or user interaction is required, and the attack is exploitable over the network (Github Advisory, pymetasploit3 repo).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary commands through the Metasploit console, with full control over Metasploit sessions and the ability to manipulate or hijack existing sessions. The impact spans high integrity and availability compromise on the vulnerable system, with moderate confidentiality exposure. Because pymetasploit3 is typically used in automated penetration testing pipelines, exploitation could enable an attacker to pivot through the Metasploit infrastructure to reach additional targets or exfiltrate sensitive session data (Github Advisory, Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.32% (55th percentile), indicating a moderate relative probability of exploitation within 30 days (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The vulnerability is detectable by Qualys scanner (detection ID 5010479) (Feedly).
console.run_module_with_output() as a module option value (e.g., RHOSTS).RHOSTS to a value such as 192.168.1.1\nsessions -i 1 or 192.168.1.1\nrun post/multi/manage/shell_to_meterpreter.run_module_with_output() sends the command to the Metasploit console, the newline causes the console to interpret the injected text as a separate command.set RHOSTS or similar option-setting commands; log entries containing embedded newline sequences in option values.post/multi/manage/shell_to_meterpreter, post/multi/recon/local_exploit_suggester) without corresponding operator activity; new or unexpected Metasploit sessions appearing in sessions -l output.The GitHub Advisory notes that no patched version has been officially released as of the advisory publication date, and the affected version range is listed as ≤ 1.0.6 with "Patched versions: None" (Github Advisory). Users should monitor the pymetasploit3 repository for a patched release. In the interim, implement strict input validation and sanitization — specifically stripping or rejecting newline characters (\n, \r) — for any externally influenced data passed as module option values. Additionally, restrict network access to Metasploit RPC interfaces using firewall rules, and review Metasploit session logs regularly for signs of unauthorized command injection.
The vulnerability was covered by The Hacker Wire with a dedicated write-up on the newline injection mechanism (The Hacker Wire). Security community discussion was observed on Mastodon (infosec.exchange) and Bluesky shortly after disclosure. The vulnerability was also indexed by INCIBE-CERT and multiple CVE aggregation platforms, indicating broad awareness within the security community (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."