JavaScript Template Engine Vulnerability in Velocity.js by Shepherdwind
CVE-2026-73649
9.8CRITICAL
What is CVE-2026-73649?
Velocity.js, a JavaScript implementation of the Apache Velocity template engine, is susceptible to a security vulnerability that allows attackers to execute arbitrary commands on the server. Specifically, prior to version 2.1.7, the #set handler inadequately validated property-read expressions, leading to potential exploitation. Attackers could leverage this weakness to gain access to shell commands, environment variables, cloud credentials, and internal network resources through an attacker-controlled template. The issue has been resolved in version 2.1.7, which includes enhanced filtering processes that secure both the assignment targets and property-read expressions.
Affected Version(s)
velocity.js < 2.1.7
