SCA: security update for www.velocidex.com/golang/velociraptor (GHSA-gpfc-mph4-qm24)

medium Tenable Cloud Security Plugin ID 435601

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can
be used to do anything and usually run with elevated permissions. To limit access to some dangerous
artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. The
Admin.Client.UpdateClientConfig is an artifact used to update the client's configuration. This artifact
did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions
(normally given by the "Investigator" role) to collect it from endpoints and update the configuration.
This can lead to arbitrary command execution and endpoint takeover. To successfully exploit this
vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the
COLLECT_CLIENT given typically by the "Investigator' role). (CVE-2025-6264)

See Also

https://github.com/advisories/GHSA-gpfc-mph4-qm24

Plugin Details

Severity: Medium

ID: 435601

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 10/13/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.1

Percentile: 96.85

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.4

Vector: CVSS2#AV:N/AC:H/Au:M/C:P/I:P/A:P

CVSS Score Source: CVE-2025-6264

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 5

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/20/2025

Vulnerability Publication Date: 6/20/2025

Reference Information

CVE: CVE-2025-6264

cwe: CWE-276