Showing 2 vulnerabilities on this page for velocity.js

Signals CISA KEV Ransomware Nuclei
shepherdwind vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix)

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts remained unfiltered. The getReferences() flow called getAttributes(), whose property access allowed an attacker-controlled template to traverse constructor.constructor to the JavaScript Function cons

CWE-94Aug 13, 2026
CVSS9.8v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Velocity.js: Prototype Pollution in #set path assignment

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it is possible to modify Object.prototype, potentially leading to Denial of Service (DoS) or Remote Code Execution (RCE) depending on the server environment.

CWE-1321May 26, 2026
CVSS8.3v3.1EPSS0.505%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX