MEDIUM

CVE-2026-9153

Gnu Sed 2026-06-25 CVSS v3.1
CVSS
6.5

Description

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation.

Summary dbcve.org

The Rapid7 InsightConnect Sed Plugin on Linux contains an arbitrary file read vulnerability that allows authenticated attackers to read any file on the host system through the expression parameter due to insufficient input validation.

Mitigation

Apply vendor patches/updates to the InsightConnect Sed Plugin and implement strict input validation on the expression parameter to prevent path traversal.

Weakness (CWE)

CWE-22 Path Traversal
CWE-200 Information Exposure

EPSS Score

0.45%
Probability of exploitation in next 30 days
38.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE