CVE-2026-19584: Velociraptor VQL injection during notebook restore from backup
Published on 2026-07-31
Vulnogram
CVSS · HIGH · 7.7 ⁄10 · CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Scoring scenario:
GENERAL
attackVector:
NETWORK
attackComplexity:
HIGH
privilegesRequired:
LOW
userInteraction:
REQUIRED
scope:
CHANGED
confidentialityImpact:
HIGH
integrityImpact:
HIGH
availabilityImpact:
NONE
Description
Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will evaluated at elevated permissions if the notebook's backup is subsequently restored.
Problem
CWE-1336 Improper neutralization of special elements used in a template engine
Problem
CWE-94: Improper Control of Generation of Code ('Code Injection')
Required configuration for exposure
Attacker must have at least the investigator role and must be able to modify a notebook cell.
Workarounds
Inspect the backup zip before restoring it to ensure it does not include malicious notebook contents. Do not automatically restore backup from untrusted sources.
| Product | Affected |
|---|---|
| Rapid7 Velociraptor on
Linux
source repo Default status is unaffected |
before 0.77.2 |
Credits
- Yuval Miller and Leon Kayaliev