Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit

2026-07-13T07:23:42Z624dda543c3f66a272d9cdbb8d87065c9ac5af55401dc833eeb07780f53113ea
CVE-2026-41264RCETakahiro Yokoyamaapache .htaccesscsv agentexploit moduleflowisemetasploitpersistencepeyaraprompt injectionpsExecremote code executionsecurity updatesmb-to-meterpreterunauthenticatedzdi-disclosures

What happened

Rapid7's weekly Metasploit update introduces new exploit and post-exploitation modules, most notably an exploit for Flowise CSV Agent Prompt Injection RCE (CVE-2026-41264) that permits unauthenticated remote code execution by uploading a crafted .csv which can execute arbitrary Python due to insufficient sandboxing. Other additions include an Apache .htaccess persistence module, a Peyara Remote Mouse 1.0.1 unauthenticated RCE module, and tooling for SMB-to-Meterpreter upgrades via PsExec.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
624dda543c3f66a272d9cdbb8d87065c9ac5af55401dc833eeb07780f53113ea
Enrichment time
2026-07-13T07:23:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.