No advisories yet.
Solution
No solution given by the vendor.
Workaround
Users should not designate a column as type URL if the source of the table is untrusted (e.g. the results from artifact collections where the data is under the attacker's control).
Tue, 18 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rapid7
Rapid7 velociraptor |
|
| Vendors & Products |
Rapid7
Rapid7 velociraptor |
Tue, 18 Aug 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS. | |
| Title | Velociraptor Stored XSS in URL column types | |
| Weaknesses | CWE-177 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-18T14:14:35.111Z
Reserved: 2026-07-10T08:15:06.308Z
Link: CVE-2026-15371
Updated: 2026-08-18T14:14:29.939Z
Status : Received
Published: 2026-08-18T07:16:48.927
Modified: 2026-08-18T15:16:49.067
Link: CVE-2026-15371
No data.
OpenCVE Enrichment
Updated: 2026-08-18T08:30:09Z