Vulnerabilities/

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

Severity:
High

Description

Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq (“Prototype Pollution in #set path assignment”) — that advisory blocked constructor/proto/prototype only in the #set assignment handler (set.cjs), but property read expressions are unfiltered.

Recommendation

Update the velocityjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
velocityjs
Anything's wrong? Let us know Last updated on August 13, 2026