← العودة للجدول
CVE-2026-8795
CVE-2026-8795 — A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifa
📅 2026-06-09
🟠 High 🔥 No NVD APT APT CVSS 7.8

📋 الوصف الكامل

A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a collection ZIP is inserted into a YAML template via Go's text/template without escaping. An attacker providing a crafted collection ZIP can leverage literal double quotes and newlines in the hostname to break out of th

💻 الأنظمة المتأثرة

Microsoft Windows

⚠️ نوع التهديد

APT

🔗 CVE ID

CVE-2026-8795

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v0.76.6

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←