CVE-2026-15371: RAPID7 Velociraptor
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS.
Affected products
- RAPID7 Velociraptor: before 0.77.2 (fixed in 0.77.2)
Published 2026-08-18. Last modified 2026-08-28.