Skip to content
Rapid7CVE-2026-64955

Rapid7 Velociraptor: CSV injection

Medium6.1CVE-2026-64955 · Published Aug 12, 2026 · updated Aug 28, 2026

When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution.  Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports. It is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory.

Rapid7 advisory

Affected versions

PackageAffectedFixed in
Velociraptor
Product
< 0.77.20.77.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1236

More Rapid7 advisories

All Rapid7
Advisory
A rogue Velociraptor client can upload a malformed sparse file such
Low3.5Aug 12
Rapid7 Velociraptor: improper authorization
Medium6.5Aug 12
Rapid7 Velociraptor: missing authorization
Medium6.5Aug 12
Rapid7 Velociraptor: missing authorization
High8.2Aug 12
Rapid7 Velociraptor: null pointer dereference
Medium6.5Aug 11
Rapid7 Velociraptor: authentication bypass by spoofing
High7.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.