VulnSea

velociraptor vulnerabilities

CVEs whose affected-version data names the velociraptor package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-77798Medium· 6.5
1w ago

Velociraptor contains a deadlock condition that may be triggered by authenticated users

Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.

▾ SunlitRapid7 · VelociraptorEPSS 0.20%via NVD
CVE-2026-77797Low· 3.6
1w ago

Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.

Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.

▾ SunlitRapid7 · VelociraptorEPSS 0.10%via NVD
CVE-2026-19072Critical· 9.9
1w ago

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the fiel…

▾ MidnightRapid7 · VelociraptorEPSS 0.40%via NVD
CVE-2026-19584High· 7.7
3w ago

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a mali…

▾ TwilightRapid7 · VelociraptorEPSS 0.19%via NVD
CVE-2026-19583Critical· 9.9
3w ago

Velociraptor Required Permissions bypass by using client monitoring queries

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. Howe…

▾ MidnightRapid7 · VelociraptorEPSS 0.60%via CVEORG
CVE-2025-14728Medium· 6.8
9mo ago

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write …

▾ Sunlitrapid7 · velociraptorEPSS 0.56%via NVD
velociraptor vulnerabilities (CVEs) · VulnSea