Skip to content
Rapid7CVE-2026-19200

Rapid7 Velociraptor: code injection

High8.9CVE-2026-19200 · Published Aug 24, 2026 · updated Aug 28, 2026

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.

Rapid7 advisory

Affected versions

PackageAffectedFixed in
Velociraptor
Product
< 0.77.20.77.2
Details and references

More Rapid7 advisories

All Rapid7
Advisory
A logic vulnerability
Medium5.1Aug 27
Rapid7 Velociraptor: cross-site scripting
High8.1Aug 18
A rogue Velociraptor client can upload a malformed sparse file such
Low3.5Aug 12
Rapid7 Velociraptor: improper authorization
Medium6.5Aug 12
Rapid7 Velociraptor: CSV injection
Medium6.1Aug 12
Rapid7 Velociraptor: missing authorization
Medium6.5Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.