Velocity Template Language(VTL) for JavaScript
96%
Total Score
98
97
100
100
0
| Title | Versions | Severity |
|---|---|---|
CVE-2026-73649 velocityjs is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 2.1.6. | 0.0.0 - 2.1.6 | Critical |
AIKIDO-2026-701239 velocityjs is vulnerable to Remote Code Execution (RCE) in versions 0.3.1 - 2.1.6. | 0.3.1 - 2.1.6 | Critical |
CVE-2026-44966 velocityjs is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 2.1.5. | 0.0.0 - 2.1.5 | High |
| Dependency | Last Release | Score |
|---|---|---|
debug Version ^4.3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.