Description
Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq (“Prototype Pollution in #set path assignment”) — that advisory blocked constructor/proto/prototype only in the #set assignment handler (set.cjs), but property read expressions are unfiltered.
Recommendation
Update the velocityjs package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.1.6
- Patched version(s): 2.1.7
References
Could your website be exposed too?
SmartScanner can check your website for Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Authenticated Remote Code Execution via loadReader functionName code injection in DbGate - CVE-2026-47670
- Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified - CVE-2026-69255
- OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment - CVE-2026-41900
- DbGate: Remote Code Execution via functionName injection in loadReader endpoint - CVE-2026-48017


