Medium severity6.8OSV Advisory· Published Dec 29, 2025· Updated Jun 17, 2026
CVE-2025-14728
CVE-2025-14728
Description
Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore directory. The issue occurs due to insufficient sanitization of directory names which end with a ".", only encoding the final "." AS "%2E".
Although files can be written to incorrect locations, the containing directory must end with "%2E". This limits the impact of this vulnerability, and prevents it from overwriting critical files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 0.2.1, 0.2.2, 0.2.3, …
cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:*range: <0.75.6
- (no CPE)range: <0.75.6
Patches
Vulnerability mechanics
References
1- docs.velociraptor.app/announcements/advisories/cve-2025-14728/nvdExploitPatchVendor Advisory
News mentions
0No linked articles in our index yet.