Arbitrary Code Execution Risk in Velociraptor's CSV Export Functionality
CVE-2026-64955

6.1MEDIUM

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
12 August 2026

What is CVE-2026-64955?

When exporting data to CSV from Velociraptor, certain characters in cell values can be interpreted by Microsoft Excel as executable formulas. This vulnerability allows for potential arbitrary code execution when a CSV file is opened in Excel, particularly if the file contains unsanitized characters that Excel processes as formulas. It raises concerns regarding the handling of CSV files, emphasizing the need for better data sanitization practices to prevent unwanted execution of commands through seemingly benign CSV exports.

Affected Version(s)

Velociraptor 0 < 0.77.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani (Talence Security)
.