Improper Access Control in Velociraptor's VQL Shell Feature
CVE-2025-0914
3.8LOW
What is CVE-2025-0914?
An improper access control issue exists in the VQL shell feature of Velociraptor that permits authenticated users to execute the execve() plugin, even when this action has been explicitly restricted by setting the prevent_execve flag in the configuration file. This configuration setting is rarely recommended and typically not used, so the vulnerability is limited to deployments where it has been explicitly enabled. Users should upgrade to version 0.73.4 or later to mitigate this risk.
Affected Version(s)
Velociraptor 0 < 0.73.4