Executive brief
A security vulnerability exists in the Rapid7 InsightConnect RPM Plugin for Linux, which is used to automate package management tasks. An authorized user with high-level permissions could exploit this flaw to run unauthorized commands on the underlying operating system. This could lead to unauthorized changes to the system, data access, or disruption of services.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Rapid7 InsightConnect RPM Plugin for Linux versions prior to 1.0.2. The vulnerability is rooted in insufficient input sanitization of the 'repo', 'key', and 'name' parameters during the construction of shell commands. An authenticated attacker with high privileges (PR:H) can exploit this over the network to execute arbitrary OS commands on the host system. The issue has been addressed in version 1.0.2 of the plugin.
Affected products
- Rapid7 InsightConnect RPM Plugin < 1.0.2
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory