CVE-2026-5463: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-5463 is a command injection vulnerability in the console.run_module_with_output() function of pymetasploit3, a Python3 automation library for Metasploit. Attackers can inject newline characters into module options such as RHOSTS, breaking the intended command structure and causing the Metasploit console to execute additional unintended commands. All versions through 1.0.6 are affected. The vulnerability was published on April 3, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (Github Advisory, Feedly).

Technical details

The root cause is improper neutralization of special elements used in a command (CWE-77). The console.run_module_with_output() function passes user-supplied module option values — such as RHOSTS — directly to the Metasploit console without sanitizing newline characters (\n). Because the Metasploit console interprets newlines as command delimiters, an attacker who can influence module option values can inject arbitrary additional console commands into the command stream. No authentication or user interaction is required, and the attack is exploitable over the network (Github Advisory, pymetasploit3 repo).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary commands through the Metasploit console, with full control over Metasploit sessions and the ability to manipulate or hijack existing sessions. The impact spans high integrity and availability compromise on the vulnerable system, with moderate confidentiality exposure. Because pymetasploit3 is typically used in automated penetration testing pipelines, exploitation could enable an attacker to pivot through the Metasploit infrastructure to reach additional targets or exfiltrate sensitive session data (Github Advisory, Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.32% (55th percentile), indicating a moderate relative probability of exploitation within 30 days (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The vulnerability is detectable by Qualys scanner (detection ID 5010479) (Feedly).

Exploitation steps

  1. Identify target: Locate a system running pymetasploit3 version ≤ 1.0.6 that exposes the Metasploit RPC interface (default ports 55552 or 55553) to the network, using tools such as Shodan or Censys.
  2. Gain influence over module options: Identify an application or workflow that accepts external input and passes it to console.run_module_with_output() as a module option value (e.g., RHOSTS).
  3. Craft malicious input: Construct a payload that embeds a newline character followed by an arbitrary Metasploit console command. For example, set RHOSTS to a value such as 192.168.1.1\nsessions -i 1 or 192.168.1.1\nrun post/multi/manage/shell_to_meterpreter.
  4. Inject the payload: Supply the crafted value as the module option. When run_module_with_output() sends the command to the Metasploit console, the newline causes the console to interpret the injected text as a separate command.
  5. Achieve arbitrary command execution: The injected command executes within the Metasploit console context, enabling session hijacking, execution of post-exploitation modules, or further manipulation of the Metasploit environment (Github Advisory, Feedly).

Indicators of compromise

  • Network: Unexpected or anomalous connections to Metasploit RPC ports (55552, 55553) from untrusted sources; unusual outbound connections initiated from the Metasploit host following RPC activity.
  • Logs: Metasploit console logs showing commands that were not initiated by the legitimate operator, particularly commands appearing immediately after set RHOSTS or similar option-setting commands; log entries containing embedded newline sequences in option values.
  • Process: Unexpected Metasploit post-exploitation modules executing (e.g., post/multi/manage/shell_to_meterpreter, post/multi/recon/local_exploit_suggester) without corresponding operator activity; new or unexpected Metasploit sessions appearing in sessions -l output.
  • File System: New or modified files in the Metasploit working directory or loot directory created at unexpected times, potentially indicating automated post-exploitation activity.

Mitigation and workarounds

The GitHub Advisory notes that no patched version has been officially released as of the advisory publication date, and the affected version range is listed as ≤ 1.0.6 with "Patched versions: None" (Github Advisory). Users should monitor the pymetasploit3 repository for a patched release. In the interim, implement strict input validation and sanitization — specifically stripping or rejecting newline characters (\n, \r) — for any externally influenced data passed as module option values. Additionally, restrict network access to Metasploit RPC interfaces using firewall rules, and review Metasploit session logs regularly for signs of unauthorized command injection.

Community reactions

The vulnerability was covered by The Hacker Wire with a dedicated write-up on the newline injection mechanism (The Hacker Wire). Security community discussion was observed on Mastodon (infosec.exchange) and Bluesky shortly after disclosure. The vulnerability was also indexed by INCIBE-CERT and multiple CVE aggregation platforms, indicating broad awareness within the security community (Feedly).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management