← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 07:16via CVEFeed

CVE-2026-15371 - Velociraptor Stored XSS in URL column types

Brief

CVE ID : CVE-2026-15371

Published : Aug. 18, 2026, 7:16 a. m.

  • 3 hours, 51 minutes ago

Description : Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI. The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS.

Severity: 8.1

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more..

Read more on CVEFeed