Skip to content
Please update to the latest release 0.77.3 to address Multiple CVEs.
Security Advisories

Security Advisories

The following CVEs have been noted.

Please upgrade to the current release.

Please consider subscribing to our Security Advisories RSS feed to receive timely notifications.

CVE-2026-78413 Velociraptor privilege escalation via SysmonLogForward client monitoring artifact
CVE-2026-78412 WatchEvent API streams another organization's live events
CVE-2026-78411 Velociraptor Server Metadata update with Insufficient Permission Check
CVE-2026-77798 Velociraptor Authenticated Denial of Service
CVE-2026-77797 Velociraptor Prefetch parser out of bounds
CVE-2026-64955 Velociraptor CSV Formula Injection in Export Pipeline
CVE-2026-64954 Velociraptor collect_client() Permissions Bypass
CVE-2026-64952 Velociraptor Hunt Deletion With Insufficient Permission Check
CVE-2026-64951 Velociraptor DoS triggered by Divide by Zero panic
CVE-2026-19584 Velociraptor VQL injection during notebook restore from backup.
CVE-2026-19583 Velociraptor Required Permissions bypass by using client monitoring queries.
CVE-2026-19200 Analyst overwrites live built-in artifacts through verify()
CVE-2026-19072 Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal
CVE-2026-18972 Velociraptor authenticated identity-spoofing vulnerability
CVE-2026-18860 Velociraptor incorrect Org deletion permissions check
CVE-2026-18652 Velociraptor STACK Type Download Path Bypasses Denied Prefix Check
CVE-2026-18640 Velociraptor directory traversal via the NewNotebook API
CVE-2026-18639 Velociraptor OIDC Authenticator susceptible to email spoofing
CVE-2026-18638 Velociraptor server crash via the SetPassword API
CVE-2026-18636 Velociraptor VFSGetBuffer API path deny list bypass
CVE-2026-18635 Velociraptor query plugin allows impersonation in other orgs
CVE-2026-18348 Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins
CVE-2026-17535 Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Volumes
CVE-2026-15371 Velociraptor Stored XSS in URL column types
CVE-2026-8795 YAML Injection Leading to Potential Analyst Targeting
CVE-2026-7573 GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organizations
CVE-2026-7572 Velociraptor EVTX Parser — Process Crash via Crafted .evtx File
CVE-2026-6948 Unbounded Memory Allocation in VQLResponse Result-Set Writer
CVE-2026-6863 HTTP Filestore Endpoints Misapply Permissions Across Organizations
CVE-2025-14728 Velociraptor directory traversal vulnerability
Security Advisories fixed in release 0.77.3
CVE-2025-6264 Velociraptor privilege escalation via UpdateConfig artifact
CVE-2025-0914 Velociraptor Shell Plugin prevent_execve bypass
CVE-2024-10526 Local Privilege Escalation In Windows Velociraptor Service
CVE-2023-5950 Rapid7 Velociraptor Reflected XSS
CVE-2023-2226 Velociraptor crashes while parsing some malformed PE or OLE files
CVE-2023-0242 Insufficient Permission Check In The VQL Copy() Function
CVE-2023-0290 Directory Traversal In Client Id Parameter
CVE-2026-5329 Velociraptor improper input validation in client message handler
CVE-2026-6290 Velociraptor query() plugin misapplies permissions to orgs