Metasploit Framework
The Metasploit Framework is an open-source tool released under a BSD-style license. For detailed licensing information, refer to the COPYING file.
Access the latest version of Metasploit from the Nightly Installers page.
Comprehensive documentation, including usage guides, is available at Metasploit Docs.
To set up a development environment, visit the Development Setup Guide.
Submit bugs and feature requests via the GitHub Issues tracker. New submissions can be made through the MSF-BUGv1 form.
For information on writing modules, refer to the API Documentation.
For questions and suggestions, you can:
Note: Some community members may still use IRC channels and the metasploit-hackers mailing list, though the primary support channels are now GitHub Discussions and Slack.
We recommend installation with the official Metasploit installers on Linux or macOS. Metasploit is also pre-installed with Kali.
For a manual setup, consult the Dev Environment Setup guide.
To get started with Metasploit:
msfconsole: This is the primary interface for interacting with Metasploit.To contribute to Metasploit:
Consolidate bind_address/bind_Addresses for reverse handlers
Socket#sendto removed in newer Ruby — affects dozens of call sites in lib/ and modules/
Stageless PHP Meterpreter breaks without setting the `stdapi` extension explicitly
Gitlab Critical Path Traversal CVE-2026-85706
"NoMethodError undefined method '[]' for nil" when using scanner/discovery/arp_sweep
Should we support `socketx0` convention for AARCH Windows/osx/Linux stagers?
Investigate analyze_db issue deeper
Installation Instructions Slightly Outdated - Suggested Improvements Included
Add support for deprecated module options
Add Windows AARCH64 support to fetch payloads