CVE-2022-35632: vulnerability in Rapid7 Velociraptor
XSS in User Interface
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS). This issue was resolved in Velociraptor 0.6.5-2.
Affected products
Rapid7 · VelociraptorRelated CVEs — Rapid7 Velociraptor
In the same product, most dangerous first.
CVE-2025-6264MEDIUMVelociraptor priviledge escalation via UpdateConfig artifactEPSS 1.0%CVE-2023-0290MEDIUMRapid7 Velociraptor directory traversal in client ID parameter EPSS 0.7%CVE-2026-5329HIGHRapid7 Velociraptor Improper Input Validation in Client Message HandlerEPSS 0.6%CVE-2026-19583CRITICALVelociraptor Required Permissions bypass by using client monitoring queriesEPSS 0.6%CVE-2021-3619LOWRapid7 Velociraptor Notebooks Authenticated Persistent XSSEPSS 0.6%CVE-2025-14728MEDIUMRapid7 Velociraptor Directory Traversal VulnerabilityEPSS 0.6%