velocityjs is vulnerable to Remote Code Execution (RCE)
98
Critical Risk
velocityjs evaluates property-read expressions in templates without guarding prototype-chain keys. A template that traverses constructor to reach the Function constructor can build and invoke an arbitrary function while the template is rendered. When untrusted templates are rendered, this allows execution of arbitrary code on the server. The fix blocks prototype-chain key access on property, index, and method read paths and on set-style assignment handlers.
You are affected if you are using a version that falls within the vulnerable range and your application renders untrusted Velocity templates.
velocityjs is vulnerable to Remote Code Execution (RCE) in versions 0.3.1 - 2.1.6.
Upgrade the velocityjs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant