← Vulnerability feed

Vulnerability record · CVE-2022-35630 · published 29 July 2022

CVE-2022-35630: Rapid7 velociraptor cross-site scripting vulnerability

Rapid7 · Velociraptor

A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static HTML file. This issue was resolved in Velociraptor 0.6.5-2.

6.1 CVSS 3.1 Medium EPSS 0.49% · top 60.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static HTML file. This issue was resolved in Velociraptor 0.6.5-2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-35630 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-6290Rapid7 velociraptor incorrect authorization vulnerabilityVelociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token…EPSS 0.39%8.8CVE-2023-0242Rapid7 velociraptor improper privilege management vulnerabilityRapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on th…EPSS 0.54%7.7CVE-2026-7573Rapid7 velociraptor insecure direct object reference vulnerabilityAn authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-p…EPSS 0.30%6.8CVE-2025-14728Rapid7 velociraptor path traversal vulnerabilityRapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is …EPSS 0.56%6.5CVE-2026-5329Rapid7 velociraptor improper input validation vulnerabilityRapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Veloc…EPSS 0.64%6.1CVE-2023-5950Rapid7 velociraptor cross-site scripting vulnerabilityRapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inje…EPSS 0.46%5.5CVE-2026-7572Rapid7 velociraptor vulnerabilityAn off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows a…EPSS 0.14%5.5CVE-2025-6264Rapid7 velociraptor incorrect default permissions vulnerabilityVelociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2022-35630), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.