VYPR

Velociraptor

by Velocidex

Source repositories

CVEs (29)

  • CVE-2022-35631MedJul 29, 2022
    risk 0.36cvss 5.5epss 0.00

    On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.

  • CVE-2026-77798MedSep 24, 2026
    risk 0.35cvss 6.5epss —

    Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.

  • CVE-2022-35629MedJul 29, 2022
    risk 0.35cvss 5.4epss 0.00

    Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issue was resolved in Velociraptor 0.6.5-2.

  • CVE-2026-6948MedMay 4, 2026
    risk 0.32cvss 4.9epss 0.00

    Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client…

  • CVE-2022-35632MedJul 29, 2022
    risk 0.31cvss 4.8epss 0.00

    The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS). This issue was resolved in Velociraptor 0.6.5-2.

  • CVE-2025-0914LowFeb 27, 2025
    risk 0.25cvss 3.8epss 0.00

    An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users to execute the execve() plugin in deployments where this was explicitly forbidden by configuring the prevent_execve flag in the configuration file. This…

  • CVE-2026-64951LowAug 12, 2026
    risk 0.23cvss 3.5epss 0.00

    A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The problem is a Divide by Zero bug in the ShouldPadFile() function.

  • CVE-2023-2226LowApr 21, 2023
    risk 0.21cvss 3.3epss 0.00

    Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor during parsing of maliciously malformed files.  For this attack to succeed, the attacker needs to be able to introduce malicious…

  • CVE-2026-18348MedAug 11, 2026
    risk 0.20cvss 4.1epss 0.00

    Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This…

Page 2 of 2