Cross-Site Scripting Vulnerability in Velociraptor Web GUI
CVE-2026-15371
8.1HIGH
What is CVE-2026-15371?
The Velociraptor web GUI presents a security concern where the code permits the specification of a custom URL type for table columns. This allows attackers to use any URL scheme, including malicious JavaScript schemes. When users click on these URLs, they can be exposed to Cross-Site Scripting (XSS) attacks. Proper validation and restriction of URL schemes are crucial to prevent such exploits, safeguarding users from potential security risks.
Affected Version(s)
Velociraptor Linux 0 < 0.77.2
