Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more
2026-06-28T07:23:46Z•dae61722b06d39338fb168e59bf45c66ee97279cf49faa37199bc6e49049f4be
ai-and-complianceaudiobookshelfauthentication-bypassdalfoxdll-side-loadingdonut-shellcodeexploitin-memory-ratlitellmloader-chainmetasploitnext.jsniss2ntlm-relaypaperclipprivilege-escalationsiemsql-injectionthreat-intelunauthenticated-rce
What happened
Rapid7 blog roundup: multiple Weekly Metasploit updates added new detection and exploit modules — notable inclusions are an Audiobookshelf unauthenticated API authentication bypass (CVE-2025-25205), a Paperclip unauthenticated remote code execution chain (CVE-2026-41679), a LiteLLM proxy pre-auth SQL injection scanner, a Next.js middleware authorization-bypass scanner, a Dalfox deserialization RCE, NTLM relay local privilege escalation tooling, and other exploit/enhancement modules. The site also published a detailed threat analysis of the Dropping Elephant campaign (in-memory RAT, DLL side‑lο
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- dae61722b06d39338fb168e59bf45c66ee97279cf49faa37199bc6e49049f4be
- Enrichment time
- 2026-06-28T07:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.