Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more
Rapid7 released Metasploit Framework 6.4.141 with four new modules: detection scanners for Audiobookshelf auth bypass (CVE-2025-25205), LiteLLM pre-auth SQL injection (CVE-2026-42208, CVSS 9.3), and Next.js middleware authorization bypass (CVE-2025-29927, CVSS 9.1), plus an exploit module for Dalfox Server deserialization RCE (CVE-2026-45087). Additional improvements include enhanced auth_brute mixin reporting and rex-socket UDP compatibility updates.