The Velociraptor project was lucky to receive a number of security advisories recently. A number of talented and experienced security researchers shared their findings and thorough reviews with our team.
We would like to extend our gratitude to the following researchers for responsibly sharing their findings:
There were a large number of advisories, the majority fell into some broad categories.
Velociraptor started off being a DFIR tool used by a small trusted team. As the project matured, it has developed enterprise security features:
Although most users still use the tool within a small trusted team it is important to ensure that the user ACLs are properly enforced. The recent round of security reviews tackled the Velociraptor security model and assisted in locking down any bypasses.
The following vulnerabilities are examples where a malicious authenticated user of the Velociraptor GUI can exceed their allowed permissions.
Other vulnerabilities identify bugs in parsing edge conditions leading to possible crashes.
The researchers have highlighted some design issues and helped to harden Velociraptor
CVE-2026-18639: Velociraptor OIDC Authenticator susceptible to email spoofing
CVE-2026-64955: Velociraptor CSV Formula Injection in Export Pipeline
To fix these issues and others, we recommend users upgrade to the latest 0.77.2 release. If you would rather not upgrade to the latest release, you can update to the latest build from the previous 0.76.7 release.