Vulnerability library
Security checkAugust 13, 2026

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmvelocityjs

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq (“Prototype Pollution in #set path assignment”) — that advisory blocked constructor/proto/prototype only in the #set assignment handler (set.cjs), but property read expressions are unfiltered.

Recommendation

Update the velocityjs package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 2.1.6
  • Patched version(s): 2.1.7

References

Could your website be exposed too?

SmartScanner can check your website for Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix) and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated August 13, 2026