A vulnerability classified as very critical was found in Rapid7 Velociraptor up to 0.77.1. Impacted is an unknown function of the component CSV file Handler. Such manipulation leads to csv injection.

This vulnerability is documented as CVE-2026-64955. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.