What is CVE-2026-64955?
CVE-2026-64955 is a sanitization vulnerability in Velociraptor where exported CSV files are not properly neutered against formula injection attacks. When these files are opened in Microsoft Excel, cells starting with certain characters can be executed as formulas, leading to arbitrary code execution, affecting exports from the GUI, offline collector, and data export functionalities. Users should update to the latest patched version to mitigate the risk.
Azərbaycanca: CVE-2026-64955, Velociraptor platformunda CSV ixracı zamanı Microsoft Excel-in müəyyən simvollarla başlayan xanaları düstur (formula injection) kimi icra etməsinə səbəb olan sanitizasiya zəifliyidir. Bu boşluq GUI, offline collector və data export funksiyaları vasitəsilə ixrac edilən faylları təsir edir; istifadəçilər ixrac edilmiş CSV faylları Microsoft Excel ilə açarkən ixtiyari kod icrası riski ilə üzləşə bilərlər. Problemi aradan qaldırmaq üçün Velociraptor-un son versiyasına yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: Microsoft
FAQ2
Which functionalities of Velociraptor are affected by CVE-2026-64955?
CVE-2026-64955 affects CSV files exported via the GUI, offline collector, and data export functionalities of Velociraptor.
What should be done to mitigate the risk of CVE-2026-64955?
To mitigate the risk of CVE-2026-64955, users should update to the latest patched version of Velociraptor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.