Rapid7 · Velociraptor · CVE-2026-18640
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
The NewNotebook API fails to properly sanitize parameters, enabling an authenticated user with `NOTEBOOK EDIT` permissions to write notebook records outside the organization's data store directory. While the written file must use the `.json.db` extension, this flaw allows the overwriting of other metadata files, including ACL records and hunts, which can lead to significant data corruption.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.