Rapid7CVE-2026-18640
Rapid7 Velociraptor: path traversal
High7.1CVE-2026-18640 · Published Aug 11, 2026 · updated Aug 28, 2026
The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Velociraptor Product | < 0.77.2 | 0.77.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-22
More Rapid7 advisories
All Rapid7| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Rapid7 Velociraptor: null pointer dereference | Medium6.5 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: authentication bypass by spoofing | High7.3 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: improper authorization | High7.2 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: authentication bypass | Medium6.8 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: improper permission handling | High8.7 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: denial of service | Medium6.2 | 0.77.2 |