Impact
Velociraptor’s notebook backup feature stores notebook cells in a zip file. When the backup is restored, the cell contents are interpolated into a template without access control checks. A user who holds the NOTEBOOK_EDITOR role can embed a VQL query inside a notebook cell that will be evaluated during restoration at higher privileges. This means that code supplied in the notebook can run with elevated rights during restoration.
Affected Systems
The vulnerability affects Rapid7 Velociraptor deployments that enable the default daily notebook backup feature. No specific product version is listed in the advisory, so all instances with this feature active are considered vulnerable.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity vulnerability. EPSS information is not available, and the issue is not currently listed in CISA KEV, suggesting that widespread exploitation has not yet been observed. The likely attack vector is an internal threat or a compromised backup file: an attacker with NOTEBOOK_EDITOR access can craft a malicious backup, or a malicious actor could supply a backup from an untrusted source. Since no access control checks are performed during restoration, the notebook content from a restored backup is automatically evaluated.
OpenCVE Enrichment