CVE-2026-64955
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/08/2026
Last modified:
12/08/2026
Description
When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. <br />
<br />
Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports.<br />
<br />
It is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM



