CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2357

As cited

Copy frozen at (site build).

vulnerabilities

Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit

Metasploit released new exploit modules for three vulnerabilities: FlowiseAI CSV Agent (CVE-2026-41264), an unauthenticated remote code execution flaw allowing attackers to upload malicious CSV files; macOS PackageKit (CVE-2024-27822), a privilege escalation vulnerability in ZSH environment handling; and Apache .htaccess persistence for Linux systems. The update also includes enhancements to FTP fingerprinting, library reloading, MCP Server tools, and certificate tracing functionality.

Why it matters: Security practitioners should review patches for Flowise versions 1.3.0 through 3.0.13 and macOS versions 14.4, 13.6.6, 12.7.4, and 11 or earlier, as these vulnerabilities enable unauthenticated remote code execution and local privilege escalation respectively.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit

Metasploit released new exploit modules for three vulnerabilities: FlowiseAI CSV Agent (CVE-2026-41264), an unauthenticated remote code execution flaw allowing attackers to upload malicious CSV files; macOS PackageKit (CVE-2024-27822), a privilege escalation vulnerability in ZSH environment handling; and Apache .htaccess persistence for Linux systems. The update also includes enhancements to FTP fingerprinting, library reloading, MCP Server tools, and certificate tracing functionality.

Why it matters: Security practitioners should review patches for Flowise versions 1.3.0 through 3.0.13 and macOS versions 14.4, 13.6.6, 12.7.4, and 11 or earlier, as these vulnerabilities enable unauthenticated remote code execution and local privilege escalation respectively.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary