Executive brief
Velociraptor is an endpoint visibility and response platform used by organizations to hunt for threats and collect forensic data. An authenticated user with notebook-editing permissions can exploit insufficient input validation in the NewNotebook API to write files outside the intended data directory, potentially overwriting critical metadata files like access control lists and corrupting the system's ability to manage security policies and operational data.
Technical details
The NewNotebook API fails to properly sanitize file path parameters, allowing directory traversal attacks via path sequences. An authenticated attacker with NOTEBOOK_EDIT permission can craft requests to write .json.db files outside the organization's designated data store directory, potentially overwriting sensitive metadata files including ACLs, hunts, and other system records. This vulnerability requires prior authentication and specific permissions, limiting the attack surface. Successful exploitation can cause data corruption and system instability. A patch is available in version 0.77.2 or later.
Affected products
- Velociraptor Velociraptor before 0.77.2
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Fixed in version 0.77.2