PT-2025-53780 · Rapid7 · Rapid7 Velociraptor
Chebua
·
Published
2025-12-29
·
Updated
2026-02-20
·
CVE-2025-14728
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Rapid7 Velociraptor versions before 0.75.6
Description
Rapid7 Velociraptor versions prior to 0.75.6 contain a directory traversal issue on Linux servers. This allows a malicious client to upload a file that is written outside the intended datastore directory. The issue stems from inadequate sanitization of directory names ending with a ".", where only the final "." is encoded as "%2E". While files can be written to incorrect locations, the containing directory must end with "%2E", limiting the potential impact and preventing overwriting of critical files.
Recommendations
Rapid7 Velociraptor versions prior to 0.75.6 should be updated to version 0.75.6 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rapid7 Velociraptor