Executive brief
Rapid7 InsightConnect is an automation platform used by security teams to streamline workflows. A vulnerability in its AWK plugin allows attackers to run unauthorized commands on the underlying Linux system. This could lead to a full system takeover, data theft, or disruption of security automation processes.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Rapid7 InsightConnect AWK Plugin for Linux. The flaw is located within the 'process_string' action, where the 'text' and 'expression' parameters are used to construct shell commands without sufficient sanitization. A remote attacker can exploit this by providing specially crafted input to execute arbitrary OS commands in the context of the plugin's processing pipeline. While the attack vector is network-based, the CVSS score reflects high complexity (AC:H), likely due to specific configuration or workflow requirements. The issue is resolved in version 1.2.2.
Affected products
- Rapid7 InsightConnect AWK Plugin < 1.2.2
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory