CVE-2026-15371: RAPID7 Velociraptor

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS.

Affected products

  • RAPID7 Velociraptor: before 0.77.2 (fixed in 0.77.2)

Published 2026-08-18. Last modified 2026-08-28.