Rapid7 Velociraptor是美国Rapid7公司开源的一款终端安全与响应工具。 Rapid7 Velociraptor 0.77.2之前版本存在输入验证错误漏洞,该漏洞源于Velociraptor导出CSV时未对以特定字符开头的单元格进行清理,可能导致Microsoft Excel将数据作为公式执行,造成任意代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Rapid7 | Velociraptor | < 0.77.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rapid7 | Velociraptor | 0 ~ 0.77.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64954 | 8.2 HIGH | Velociraptor collect_client() Permissions Bypass |
| CVE-2026-18652 | 6.5 MEDIUM | Velociraptor STACK Type Download Path Bypasses Denied Prefix Check |
| CVE-2026-64952 | 6.5 MEDIUM | Velociraptor Hunt Deletion With Insufficient Permission Check |
| CVE-2026-64951 | 3.5 LOW | Velociraptor DoS triggered by Divide by Zero panic |
No comments yet