Executive brief
Velociraptor is a digital forensics and endpoint management platform used by security teams to conduct investigations and collect data from endpoints. A flaw in the verify() function allows users with analyst privileges (NOTEBOOK_EDIT permission) to overwrite critical built-in artifacts that should be read-only, potentially compromising the integrity of investigations and enabling malicious query execution across the platform.
Technical details
The verify() VQL function, intended to validate artifact syntax and configuration, fails to properly enforce permission checks when accessing the global artifact repository. An attacker with the NOTEBOOK_EDIT permission (typically granted to analysts) can exploit this flaw to overwrite existing artifacts without proper authorization. The vulnerability allows direct manipulation of production artifacts through the verify() plugin, which incorrectly uses a global repository instead of a sandboxed temporary repository. This privilege escalation can be leveraged to inject malicious VQL code into artifacts that execute during normal platform operations. The fix involves using a temporary repository specifically for the verify() function, preventing modifications to the live artifact store.
Affected products
- Velocidex Velociraptor before 0.77.2
Timeline
- 2026-08-24: disclosed
- 2026-08-07: patched: Fix merged in PR #4962; version 0.77.2 released with patch