Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more
2026-06-27T07:23:46Z•d2465029bf76c088671df2db3cc7a1c342e1af3bac35559f71df40c8872b5f42
audiobookshelfauthentication-bypassdll-side-loadingdonut-shellcodedropping-elephantexploit-modulememory-resident-malwaremetasploitnist-nis2ntlm-relaypaperclipsql-injectionthreat-intelunauthenticated-rce
What happened
Rapid7 released a Metasploit framework update adding multiple new exploit and scanner modules that materially lower the bar for attackers: notable additions include an Audiobookshelf unauthenticated API authentication bypass detector (CVE-2025-25205), a BerriAI LiteLLM proxy pre-auth SQL injection scanner, Next.js middleware authorization bypass scanning, a Dalfox deserialization RCE scanner, and an exploit for Paperclip AI allowing unauthenticated full remote code execution (CVE-2026-41679). The release also includes a local NTLM relay privilege escalation module, post-exploitation/automation
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- d2465029bf76c088671df2db3cc7a1c342e1af3bac35559f71df40c8872b5f42
- Enrichment time
- 2026-06-27T07:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.