www.velocidex.com/golang/velociraptor
Activity
- Latest release
- 1mo ago
- Total releases
- 56
- Cadence
- ~34 days
- Last 12 months
- 11
Details
- First release
- Jul 15, 2019
| Version | Released | |
|---|---|---|
v0.77.2
patch
3 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev |
v0.77.2
patch
Dependencies (150)
+ 142 more |
|
v0.76.7
patch
3 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev |
v0.76.7
patch
Dependencies (148)
+ 140 more |
|
v0.77.1
minor
3 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev |
v0.77.1
minor
Dependencies (150)
+ 142 more |
|
v0.77.1-rc1
pre
3 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev |
v0.77.1-rc1
pre
Dependencies (149)
+ 141 more |
|
v0.76.6
patch
3 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev |
v0.76.6
patch
Dependencies (148)
+ 140 more |
|
v0.76.4
patch
3 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev |
v0.76.4
patch
Dependencies (148)
+ 140 more |
|
v0.75.7
patch
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.75.7
patch
Dependencies (144)
+ 136 more |
|
v0.76.2
patch
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.76.2
patch
Dependencies (148)
+ 140 more |
|
v0.76.1-rc1
pre
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.76.1-rc1
pre
Dependencies (147)
+ 139 more |
|
v0.75.6
patch
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.75.6
patch
Dependencies (144)
+ 136 more |
|
v0.75.5
patch
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.75.5
patch
Dependencies (143)
+ 135 more |
|
v0.75.2
patch
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.75.2
patch
Dependencies (140)
+ 132 more |
|
v0.75.1
minor
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.75.1
minor
Dependencies (140)
+ 132 more |
|
v0.74.5
patch
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.74.5
patch
Dependencies (139)
+ 131 more |
|
v0.74.4
patch
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.74.4
patch
Dependencies (139)
+ 131 more |
|
v0.74.3
patch
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.74.3
patch
Dependencies (139)
+ 131 more |
|
v0.74.2
minor
5 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.74.2
minor
Dependencies (139)
+ 131 more |
|
v0.76.1
minor
4 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev |
v0.76.1
minor
Dependencies (136)
+ 128 more |
|
v0.7.0-3
pre
5 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.7.0-3
pre
Dependencies (115)
+ 107 more |
|
v0.6.9-rc1
pre
5 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.9-rc1
pre
Dependencies (110)
+ 102 more |
|
v0.6.8-1
pre
5 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.8-1
pre
Dependencies (107)
+ 99 more |
|
v0.6.8-rc2
pre
5 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.8-rc2
pre
Dependencies (107)
+ 99 more |
|
v0.6.7-5
pre
5 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.7-5
pre
Dependencies (104)
+ 96 more |
|
v0.6.7-4
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.7-4
pre
Dependencies (104)
+ 96 more |
|
v0.6.7-rc3
pre
5 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.7-rc3
pre
Dependencies (103)
+ 95 more |
|
v0.6.6-rc1
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.6-rc1
pre
Dependencies (103)
+ 95 more |
|
v0.6.5-0
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.5-0
pre
Dependencies (103)
+ 95 more |
|
v0.6.4-2
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.4-2
pre
Dependencies (103)
+ 95 more |
|
v0.6.4-1
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.4-1
pre
Dependencies (103)
+ 95 more |
|
v0.6.4-rc1
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.4-rc1
pre
Dependencies (103)
+ 95 more |
|
v0.6.3
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.3
patch
Dependencies (103)
+ 95 more |
|
v0.6.3-rc1
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.3-rc1
pre
Dependencies (103)
+ 95 more |
|
v0.6.2
minor
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.2
minor
Dependencies (99)
+ 91 more |
|
v0.6.2-rc1
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.2-rc1
pre
Dependencies (98)
+ 90 more |
|
v0.6.1-rc1
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.1-rc1
pre
Dependencies (96)
+ 88 more |
|
v0.6.0-rc1
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.6.0-rc1
pre
Dependencies (94)
+ 86 more |
|
v0.5.9
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.9
patch
Dependencies (92)
+ 84 more |
|
v0.5.9-rc1
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.9-rc1
pre
Dependencies (91)
+ 83 more |
|
v0.5.7
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.7
patch
Dependencies (88)
+ 80 more |
|
v0.5.6
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.6
patch
Dependencies (87)
+ 79 more |
|
v0.5.5-1
pre
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.5-1
pre
Dependencies (87)
+ 79 more |
|
v0.5.4
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.4
patch
Dependencies (86)
+ 78 more |
|
v0.5.3
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.3
patch
Dependencies (86)
+ 78 more |
|
v0.5.0
minor
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (83)
+ 75 more |
|
v0.4.9
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.9
patch
Dependencies (83)
+ 75 more |
|
v0.4.8
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.8
patch
Dependencies (84)
+ 76 more |
|
v0.4.7
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.7
patch
Dependencies (80)
+ 72 more |
|
v0.4.4
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.4
patch
Dependencies (80)
+ 72 more |
|
v0.4.2
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.2
patch
Dependencies (79)
+ 71 more |
|
v0.4.1
patch
7 CVEs
CVE-2026-6290
GO-2026-5438
GHSA-hv5g-26jg-pc45
Jun 25, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token in www.velocidex.com/golang/velociraptor References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7572
GO-2026-5174
GHSA-6cmp-qv2f-x97x
Jun 25, 2026
Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an off-by-one error in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-7573
GO-2026-5078
GHSA-3c93-g9g6-p5j4
Jun 25, 2026
Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an authorization bypass vulnerability in www.velocidex.com/golang/velociraptor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: www.velocidex.com/golang/velociraptor before v0.76.5. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6863
GO-2026-4997
GHSA-2v93-vp82-cjv8
May 20, 2026
Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Velocidex Velociraptor has an Incorrect Authorization issue in www.velocidex.com/golang/velociraptor Fixed in
0.76.4
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-6264
GO-2025-3768
GHSA-gpfc-mph4-qm24
Jul 28, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor Fixed in
0.74.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0242
GO-2023-1527
GHSA-g5vm-525q-r66c
Aug 20, 2024
Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0290
GO-2023-1502
GHSA-7jf5-fvgf-48c6
Aug 20, 2024
Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Velociraptor subject to Path Traversal in www.velocidex.com/golang/velociraptor Fixed in
0.6.7-5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.4.1
patch
Dependencies (77)
+ 69 more |