VYPR

Velociraptor

by Velocidex

Source repositories

CVEs (23)

  • CVE-2026-64951LowAug 12, 2026
    risk 0.23cvss 3.5epss 0.00

    A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The problem is a Divide by Zero bug in the ShouldPadFile() function.

  • CVE-2023-2226LowApr 21, 2023
    risk 0.21cvss 3.3epss 0.00

    Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor during parsing of maliciously malformed files.  For this attack to succeed, the attacker needs to be able to introduce malicious…

  • CVE-2026-18348MedAug 11, 2026
    risk 0.20cvss 4.1epss 0.00

    Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This…

Page 2 of 2