OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation.
References
| Link | Resource |
|---|---|
| https://extensions.rapid7.com/extension/sed | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-06-25 01:16
Updated : 2026-06-27 19:24
NVD link : CVE-2026-9155
Mitre link : CVE-2026-9155
CVE.ORG link : CVE-2026-9155
JSON object : View
Products Affected
linux
- linux_kernel
gnu
- sed
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
