Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more

2026-06-27T19:23:58Z2e343e5cccfc896bfddc039b0b6d0cf42fa3af2e2b2692733a2adee49c22422a
CVE-2025-25205audiobookshelfauthorization-bypasscvE-2026-41679dalfoxdeserialization-rcedll-side-loadingdonut-shellcodedropping-elephantexploit-moduleslitellmmalwaremcp-servermemory-resident-ratmetasploitnextjsnis2ntlm-relaypaperclippersistenceprivilege-escalationsiemsql-injectionthreat-huntingunauthenticated-rce

What happened

Rapid7 published multiple updates and research items: a Weekly Metasploit update adding new detection/exploit modules (including an Audiobookshelf unauthenticated API auth bypass for CVE-2025-25205, a LiteLLM proxy pre-auth SQL injection scanner, a Next.js middleware auth-bypass scanner, and a Dalfox deserialization RCE detection), and a separate Metasploit release that adds several exploits including an unauthenticated full RCE against Paperclip (CVE-2026-41679), an NTLM-relay local privilege escalation module, Xerte arbitrary file upload, and other post-exploitation enhancements (MCP server/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
2e343e5cccfc896bfddc039b0b6d0cf42fa3af2e2b2692733a2adee49c22422a
Enrichment time
2026-06-27T19:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more · Baitaphish