Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit
2026-07-13T07:23:42Z•624dda543c3f66a272d9cdbb8d87065c9ac5af55401dc833eeb07780f53113ea
CVE-2026-41264RCETakahiro Yokoyamaapache .htaccesscsv agentexploit moduleflowisemetasploitpersistencepeyaraprompt injectionpsExecremote code executionsecurity updatesmb-to-meterpreterunauthenticatedzdi-disclosures
What happened
Rapid7's weekly Metasploit update introduces new exploit and post-exploitation modules, most notably an exploit for Flowise CSV Agent Prompt Injection RCE (CVE-2026-41264) that permits unauthenticated remote code execution by uploading a crafted .csv which can execute arbitrary Python due to insufficient sandboxing. Other additions include an Apache .htaccess persistence module, a Peyara Remote Mouse 1.0.1 unauthenticated RCE module, and tooling for SMB-to-Meterpreter upgrades via PsExec.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 624dda543c3f66a272d9cdbb8d87065c9ac5af55401dc833eeb07780f53113ea
- Enrichment time
- 2026-07-13T07:23:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.