CVE Tools

Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more

Rapid7 BlogBy Simon Janusz

ResearchAudiobookshelfBerriAI LiteLLM Proxy

Our summary

Rapid7’s Metasploit Framework update introduces new scanners and an exploit module, including a Next.js Middleware Authorization Bypass scanner for CVE-2025-29927, a LiteLLM proxy pre-auth SQL injection scanner for CVE-2026-42208, and an unauthenticated Audiobookshelf API authentication bypass scanner for CVE-2025-25205 (fixed in 2.19.1 for affected releases 2.17.0–2.19.0). The release also adds a Dalfox found-action deserialization RCE exploit for Dalfox Server versions <= 2.12.0 tied to CVE-2026-45087. These additions matter because they help detect and potentially validate high-impact pre-auth and authorization flaws, as well as remote code execution via unsafe deserialization paths.

Read at Rapid7 Blog

Rapid7 Blog publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store