{"api_version":"1","generated_at":"2026-08-16T20:47:43+00:00","cve":"CVE-2026-64955","urls":{"html":"https://cve.report/CVE-2026-64955","api":"https://cve.report/api/cve/CVE-2026-64955.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64955","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64955"},"summary":{"title":"Velociraptor CSV Formula Injection in Export Pipeline","description":"When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. \n\nVelociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports.\n\nIt is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory.","state":"PUBLISHED","assigner":"rapid7","published_at":"2026-08-12 10:17:20","updated_at":"2026-08-12 13:17:23"},"problem_types":["CWE-1236","CWE-1236 CWE-1236 Improper neutralization of formula elements in a CSV file"],"metrics":[{"version":"3.1","source":"cve@rapid7.com","type":"Secondary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"http://docs.velociraptor.app/announcements/advisories/cve-2026-64955/","name":"http://docs.velociraptor.app/announcements/advisories/cve-2026-64955/","refsource":"cve@rapid7.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64955","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64955","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Rapid7","product":"Velociraptor","version":"affected 0.77.2 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Never open exported CSV files using Microsoft Excel or Google Docs. Libreoffice was tested to not be vulnerable to this issue so it can be used safely.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Tristan Madani (Talence Security)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64955","cve":"CVE-2026-64955","epss":"0.003640000","percentile":"0.293370000","score_date":"2026-08-12","updated_at":"2026-08-13 00:04:46"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-64955","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-12T12:29:19.765452Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-12T12:29:40.570Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Velociraptor","repo":"https://github.com/Velocidex/velociraptor/","vendor":"Rapid7","versions":[{"lessThan":"0.77.2","status":"affected","version":"0","versionType":"semver"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"This is only an issue if the exported CSV files are subsequently opened in Microsoft Excel."}],"value":"This is only an issue if the exported CSV files are subsequently opened in Microsoft Excel."}],"credits":[{"lang":"en","type":"finder","value":"Tristan Madani (Talence Security)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution.&nbsp;</p><div>Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports.</div><div>It is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory.</div>"}],"value":"When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. \n\nVelociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports.\n\nIt is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory."}],"impacts":[{"capecId":"CAPEC-242","descriptions":[{"lang":"en","value":"CAPEC-242 Code Injection"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1236","description":"CWE-1236 Improper neutralization of formula elements in a CSV file","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-12T09:39:26.928Z","orgId":"9974b330-7714-4307-a722-5648477acda7","shortName":"rapid7"},"references":[{"url":"http://docs.velociraptor.app/announcements/advisories/cve-2026-64955/"}],"source":{"discovery":"UNKNOWN"},"title":"Velociraptor CSV Formula Injection in Export Pipeline","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Never open exported CSV files using Microsoft Excel or Google Docs. Libreoffice was tested to not be vulnerable to this issue so it can be used safely."}],"value":"Never open exported CSV files using Microsoft Excel or Google Docs. Libreoffice was tested to not be vulnerable to this issue so it can be used safely."}],"x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"9974b330-7714-4307-a722-5648477acda7","assignerShortName":"rapid7","cveId":"CVE-2026-64955","datePublished":"2026-08-12T09:39:26.928Z","dateReserved":"2026-07-21T08:32:47.510Z","dateUpdated":"2026-08-12T12:29:40.570Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-12 10:17:20","lastModifiedDate":"2026-08-12 13:17:23","problem_types":["CWE-1236","CWE-1236 CWE-1236 Improper neutralization of formula elements in a CSV file"],"metrics":{"cvssMetricV31":[{"source":"cve@rapid7.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-12T12:29:19.765452Z","id":"CVE-2026-64955","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64955","Ordinal":"1","Title":"Velociraptor CSV Formula Injection in Export Pipeline","CVE":"CVE-2026-64955","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64955","Ordinal":"1","NoteData":"When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. \n\nVelociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports.\n\nIt is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory.","Type":"Description","Title":"Velociraptor CSV Formula Injection in Export Pipeline"}]}}}