CVE-2017-5231: RAPID7 Metasploit

High severity, CVSS 7.1. EPSS: 1.2% chance of exploitation in the next 30 days.

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

Affected products

  • RAPID7 Metasploit: up to and including 4.13.19

Published 2017-03-02. Last modified 2026-06-17.