CVE-2026-64955

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/08/2026
Last modified:
12/08/2026

Description

When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. <br /> <br /> Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports.<br /> <br /> It is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory.