Vulnerabilities/

Velocity.js has a Prototype Pollution vulnerability through #set path assignment

Severity:
High

Description

A prototype pollution vulnerability was discovered in Velocity.js <= 2.1.5. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it is possible to modify Object.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
velocityjs
Anything's wrong? Let us know Last updated on May 09, 2026