GHSA-7gfh-x38p-prh3
CRITICALRemote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq ("Prototype Pollution in #set path assignment") — that advisory blocked constructor/proto/prototype only in the #set assignment handler (set.cjs), but property read expressions are unfiltered. Any application rendering attacker-controlled Velocity templates
- Affected
- >=0, <2.1.7, <= 2.1.6
- Fixed in
- 2.1.7
- Weakness
- CWE-94
- Published
- 2026-07-24
- Source
- osv