Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit
2026-07-11T19:23:48Z•513845f7447f61cb6fc255b9bfe115443a2494fb90c53abdc80829209fd9f22d
AI offensiveApache .htaccessCSV injectionCVE-2026-41264FlowisePeyara Remote MousePsExecSMB to Meterpreterdisclosuremetasploitmod_cgi web shellred teamingsandbox bypassunauthenticated RCEvulnerability management
What happened
Rapid7 weekly updates and blog posts highlight several new Metasploit modules and security themes: a new exploit for Flowise AI’s CSV Agent enabling unauthenticated RCE by uploading a crafted .csv that executes arbitrary Python (CVE-2026-41264) due to insufficient sandboxing; a Linux Apache .htaccess persistence module that plants a mod_cgi .htaccess web shell; an unauthenticated RCE module for Peyara Remote Mouse 1.0.1; and a post module to upgrade authenticated SMB sessions to Meterpreter via PsExec. Rapid7 also discusses broader AI-driven offensive/defensive trends (multi-agent red team AI,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 513845f7447f61cb6fc255b9bfe115443a2494fb90c53abdc80829209fd9f22d
- Enrichment time
- 2026-07-11T19:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.