Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
- Severity:
- High
Description
Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq (“Prototype Pollution in #set path assignment”) — that advisory blocked constructor/proto/prototype only in the #set assignment handler (set.cjs), but property read expressions are unfiltered.
Recommendation
Update the velocityjs package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.1.6
- Patched version(s): 2.1.7
References
Related Issues
- Authenticated Remote Code Execution via loadReader functionName code injection in DbGate - CVE-2026-47670
- Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified - CVE-2026-69255
- OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment - CVE-2026-41900
- DbGate: Remote Code Execution via functionName injection in loadReader endpoint - CVE-2026-48017
You might also like:
- Tags:
- npm
- velocityjs
Anything's wrong? Let us know Last updated on August 13, 2026


