A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a collection ZIP is inserted into a YAML template via Go's text/template without escaping. An attacker providing a crafted collection ZIP can leverage literal double quotes and newlines in the hostname to break out of the YAML quoted string and inject a new mount remapping entry. When an analyst applies the generated remapping file with --remap, arbitrary VQL executes on their machine with NullACLManager (all permissions granted, unsandboxed).
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a collection ZIP is inserted into a YAML template via Go's text/template without escaping. An attacker providing a crafted collection ZIP can leverage literal double quotes and newlines in the hostname to break out of the YAML quoted string and inject a new mount remapping entry. When an analyst applies the generated remapping file with --remap, arbitrary VQL executes on their machine with NullACLManager (all permissions granted, unsandboxed). | |
| Weaknesses | CWE-116 CWE-74 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-06-09T01:04:21.775Z
Reserved: 2026-05-17T23:31:05.101Z
Link: CVE-2026-8795
No data.
Status : Received
Published: 2026-06-09T01:16:47.470
Modified: 2026-06-09T01:16:47.470
Link: CVE-2026-8795
No data.
OpenCVE Enrichment
No data.