CVE-2022-35630
Velociraptor vulnerability analysis and mitigation

Overview

CVE-2022-35630 is a cross-site scripting (XSS) vulnerability discovered in Velociraptor's artifact collection report feature. The vulnerability was identified in July 2022 through a security code review performed by Tim Goddard from CyberCX and was fixed in Velociraptor version 0.6.5-2, released on July 26, 2022 (Rapid7 Blog).

Technical details

The vulnerability exists in the HTML export functionality of Velociraptor's collection report feature. When users export a collection report in HTML format, the server generates a standalone HTML file containing a collection summary. Due to improper input validation, malicious clients could inject JavaScript code into this static HTML file. The file is served locally from a file:// URL, which limits its access to server cookies and other sensitive information (Rapid7 Blog).

Impact

The impact of this vulnerability is considered low because the exported HTML file is served locally and does not have access to server cookies or other sensitive information. However, it could potentially be used to facilitate phishing attacks. Additionally, the vulnerable feature is not frequently used, which further reduces the potential impact (Rapid7 Blog).

Mitigation and workarounds

The vulnerability has been fixed in Velociraptor version 0.6.5-2, released on July 26, 2022. Users are advised to upgrade their Velociraptor servers to this version or newer to remediate the vulnerability (Rapid7 Blog).

Additional resources


SourceThis report was generated using AI

Related Velociraptor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-10526HIGH8.6
  • VelociraptorVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesNov 07, 2024
CVE-2025-14728MEDIUM6.8
  • VelociraptorVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesDec 29, 2025
CVE-2023-5950MEDIUM6.1
  • VelociraptorVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesNov 06, 2023
CVE-2025-6264MEDIUM5.5
  • VelociraptorVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesJun 20, 2025
CVE-2025-0914LOW3.8
  • VelociraptorVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesFeb 27, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management