Executive brief
A security vulnerability exists in the Rapid7 InsightConnect Traceroute plugin, which is used to diagnose network connectivity issues. An attacker can exploit this flaw to take control of the underlying system by injecting malicious commands into network diagnostic requests. This could lead to unauthorized access to sensitive data or a complete compromise of the affected server.
Technical details
An OS Command Injection vulnerability (CWE-78) exists in the 'traceroute' action of the Rapid7 InsightConnect Traceroute Plugin for Linux. The flaw is caused by insufficient input validation of several request parameters, including host, port, max_ttl, count, and time_out, which are used to construct shell commands. A remote attacker can exploit this by submitting specially crafted values for these parameters to execute arbitrary commands on the host system. The vulnerability is mitigated by a high attack complexity (AC:H) but requires no prior authentication. Users should update to version 1.0.3 or later to remediate the issue.
Affected products
- Rapid7 InsightConnect Traceroute Plugin < 1.0.3
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory