Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more

2026-06-28T19:23:46Z388adc137c44ddaac66808454cf0694fe6b631df4df5c813323f7ad3059b5bd1
audiobookshelfauth-bypassdalfoxdll-side-loadingdropping-elephantexploit-modulelitellmmcp-servermemory-resident-malwaremetasploitntlm-relaypaperclip-aisql-injectionunauthenticated-rce

What happened

Rapid7 weekly updates: new Metasploit modules include an unauthenticated API authentication bypass scanner for Audiobookshelf (affects 2.17.0–2.19.0, fixed in 2.19.1; CVE-2025-25205), a LiteLLM proxy pre-auth SQL injection scanner, a Next.js middleware authorization bypass scanner, a Dalfox deserialization RCE detector, and an exploit module for Paperclip AI unauthenticated RCE (CVE-2026-41679). Additional Metasploit enhancements include NTLM relay privilege escalation tooling, MCP server integration for AI-assisted operations, and bruteforce reporting improvements. Separate Rapid7 research: a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
388adc137c44ddaac66808454cf0694fe6b631df4df5c813323f7ad3059b5bd1
Enrichment time
2026-06-28T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more · Baitaphish