Security & Threat Intelligence · 25.07.2026, 15:29 UTC
Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more
| Schweregrad | critical aktiv ausgenutzt (KEV) |
|---|---|
| CVSS | 9.3 |
| CVE | ↗ ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Rapid7 Blog ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad kritisch (CVSS 9.3). Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Betroffene Kennungen: CVE-2025-25205, CVE-2025-29927, CVE-2026-42208, CVE-2026-45087. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Help shape the future of Metasploit FrameworkWe are planning future work in relation to the evasion capabilities present in Metasploit Framework, and how they function/are presented to users. We are currently accepting responses to our feedback form, which means that you can shape the future of how evasive capabilities are implemented in Metasploit Framework. The proposal for the changes can be found here, and you can submit your responses to the form here. The form will stop accepting responses on the 1st of July, 2026.New module content and improvements have also been added this week. This includes a Next.js Middleware Authorization Bypass scanner, LiteLLM Proxy SQL Injection, an unauthenticated API authentication bypass scanner for Audiobookshelf, a deserialization RCE in Dalfox, and improvements to service and host reporting in bruteforce-related modules.New module content (4)Audiobookshelf Unauthenticated API Authentication Bypass ScannerAuthors: Kenneth LaCroix and swiftbird07Type: AuxiliaryPull request: #21565 contributed by kenlacroixPath: scanner/http/audiobookshelf_auth_bypassAttackerKB reference: CVE-2025-25205Description: Adds audiobookshelf_auth_bypass, a detection module for CVE-2025-25205 — an unauthenticated API authentication bypass in Audiobookshelf (self-hosted audiobook/podcast server), affecting versions 2.17.0 – 2.19.0 (fixed in 2.19.1).BerriAI LiteLLM Proxy Pre-Auth SQL Injection ScannerAuthors: Kenneth LaCroix and Tencent YunDing Security LabType: AuxiliaryPull request: #21567 contributed by kenlacroixPath: scanner/http/litellm_proxy_sqliAttackerKB …