Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Users should not designate a column as type URL if the source of the table is untrusted (e.g. the results from artifact collections where the data is under the attacker's control).
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS. | |
| Title | Velociraptor Stored XSS in URL column types | |
| Weaknesses | CWE-177 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-18T06:52:28.884Z
Reserved: 2026-07-10T08:15:06.308Z
Link: CVE-2026-15371
No data.
Status : Received
Published: 2026-08-18T07:16:48.927
Modified: 2026-08-18T07:16:48.927
Link: CVE-2026-15371
No data.
OpenCVE Enrichment
No data.