CVE-2026-15371
EUVD-2026-6057118.08.2026, 07:16
Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| rapid7 | velociraptor | 𝑥 < 0.77.2 | CNA |
Common Weakness Enumeration