PT-2026-76907 · Unknown · Velociraptor

·

CVE-2026-15371

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Velociraptor (affected versions not specified)
Description The web GUI allows the specification of custom column types for tables. When the URL type is used, the system forms a clickable link from the cell value. Because the code does not restrict the allowed URL schemes, an attacker can use a JavaScript scheme to execute a Cross-Site Scripting (XSS) attack, which occurs when malicious scripts are injected into trusted websites.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15371

Affected Products

Velociraptor