← Vulnerability feed

Vulnerability record · CVE-2025-14728 · published 29 December 2025

CVE-2025-14728: Rapid7 velociraptor path traversal vulnerability

Rapid7 · Velociraptor

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore directory. The issue occurs due to insufficient sanitization of directory names which end with a ".", only encoding the final "." AS "%2E". Although files can be written to incorrect locations, the containing directory must end with "%2E". This limits the impact of this vulnerability, and prevents it from overwriting critical files.

6.8 CVSS 3.1 Medium EPSS 0.56% · top 55.6% CWE-22 · Path traversal
6.8CVSS 3.1 base score
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore directory. The issue occurs due to insufficient sanitization of directory names which end with a ".", only encoding the final "." AS "%2E". Although files can be written to incorrect locations, the containing directory must end with "%2E". This limits the impact of this vulnerability, and prevents it from overwriting critical files.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-14728 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-6290Rapid7 velociraptor incorrect authorization vulnerabilityVelociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token…EPSS 0.39%8.8CVE-2023-0242Rapid7 velociraptor improper privilege management vulnerabilityRapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on th…EPSS 0.54%7.7CVE-2026-7573Rapid7 velociraptor insecure direct object reference vulnerabilityAn authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-p…EPSS 0.30%6.5CVE-2026-5329Rapid7 velociraptor improper input validation vulnerabilityRapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Veloc…EPSS 0.64%6.1CVE-2023-5950Rapid7 velociraptor cross-site scripting vulnerabilityRapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inje…EPSS 0.46%6.1CVE-2022-35630Rapid7 velociraptor cross-site scripting vulnerabilityA cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static…EPSS 0.49%5.5CVE-2026-7572Rapid7 velociraptor vulnerabilityAn off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows a…EPSS 0.14%5.5CVE-2025-6264Rapid7 velociraptor incorrect default permissions vulnerabilityVelociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2025-14728), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.