CVE-2020-7384: RAPID7 Metasploit
High severity, CVSS 7.8. EPSS: 30.5% chance of exploitation in the next 30 days.
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.
Affected products
- RAPID7 Metasploit: before 4.19.0 (fixed in 4.19.0)
Published 2020-10-29. Last modified 2026-06-17.