JavaScript Template Engine Vulnerability in Velocity.js by Shepherdwind
CVE-2026-73649

9.8CRITICAL

Key Information:

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73649?

Velocity.js, a JavaScript implementation of the Apache Velocity template engine, is susceptible to a security vulnerability that allows attackers to execute arbitrary commands on the server. Specifically, prior to version 2.1.7, the #set handler inadequately validated property-read expressions, leading to potential exploitation. Attackers could leverage this weakness to gain access to shell commands, environment variables, cloud credentials, and internal network resources through an attacker-controlled template. The issue has been resolved in version 2.1.7, which includes enhanced filtering processes that secure both the assignment targets and property-read expressions.

Affected Version(s)

velocity.js < 2.1.7

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.