CVE-2026-15371

EUVD-2026-60571
Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS.
Hex Encoding
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
rapid7CNA
8.1 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 11.13%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
rapid7velociraptor
𝑥
< 0.77.2
CNA