MEDIUM

CVE-2026-9154

Gnu Sed 2026-06-25 CVSS v3.1
CVSS
6.5

Description

Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter.

Summary dbcve.org

Arbitrary File Write vulnerability in the Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths by manipulating the expression parameter, potentially leading to code execution or system compromise.

Mitigation

Implement strict input validation and path sanitization on the expression parameter to prevent path traversal and restrict write operations to intended directories; also apply principle of least privilege to plugin permissions.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

0.41%
Probability of exploitation in next 30 days
34.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE