← Vulnerability feed

Vulnerability record · CVE-2020-7350 · published 22 April 2020

CVE-2020-7350: Rapid7 metasploit os command injection vulnerability

Rapid7 · Metasploit

Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts untrusted user-supplied data via a remote computer's hostname or service name. An attacker can create a specially-crafted hostname or service name to be imported by Metasploit from a variety of sources and trigger a command injection on the operator's terminal. Note, only the Metasploit Framework and products that expose the plugin system is susceptible to this issue -- notably, this does not include Rapid7 Metasploit Pro. Also note, this vulnerability cannot be triggered through a normal scan operation -- the attacker would have to supply a file that is processed with the db_import command.

7.8 CVSS 3.1 High EPSS 5.0% · top 8.1% CWE-78 · OS command injection
7.8CVSS 3.1 base score, v2 6.8
5.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts untrusted user-supplied data via a remote computer's hostname or service name. An attacker can create a specially-crafted hostname or service name to be imported by Metasploit from a variety of sources and trigger a command injection on the operator's terminal. Note, only the Metasploit Framework and products that expose the plugin system is susceptible to this issue -- notably, this does not include Rapid7 Metasploit Pro. Also note, this vulnerability cannot be triggered through a normal scan operation -- the attacker would have to supply a file that is processed with the db_import command.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7350 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-7376Rapid7 metasploit relative path traversal vulnerabilityThe Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method …EPSS 1.1%8.8CVE-2020-7385Rapid7 metasploit deserialization of untrusted data vulnerabilityBy launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that…EPSS 1.8%7.8CVE-2020-7384Rapid7 metasploit command injection vulnerabilityRapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arb…EPSS 30%7.8CVE-2017-5235Rapid7 metasploit untrusted search path vulnerabilityRapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer …EPSS 0.91%7.5CVE-2019-5645Rapid7 metasploit uncontrolled resource consumption vulnerabilityBy sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expressi…EPSS 42%7.5CVE-2020-7377Rapid7 metasploit relative path traversal vulnerabilityThe Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the …EPSS 1.1%7.3CVE-2019-5624Rapid7 metasploit path traversal vulnerabilityRapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the…EPSS 2.8%7.1CVE-2017-5228Rapid7 metasploit path traversal vulnerabilityAll editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.downlo…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2020-7350), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.