PT-2025-53780 · Rapid7 · Rapid7 Velociraptor

Chebua

·

Published

2025-12-29

·

Updated

2026-02-20

·

CVE-2025-14728

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rapid7 Velociraptor versions before 0.75.6
Description Rapid7 Velociraptor versions prior to 0.75.6 contain a directory traversal issue on Linux servers. This allows a malicious client to upload a file that is written outside the intended datastore directory. The issue stems from inadequate sanitization of directory names ending with a ".", where only the final "." is encoded as "%2E". While files can be written to incorrect locations, the containing directory must end with "%2E", limiting the potential impact and preventing overwriting of critical files.
Recommendations Rapid7 Velociraptor versions prior to 0.75.6 should be updated to version 0.75.6 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-14728

Affected Products

Rapid7 Velociraptor