Executive brief
Velocity.js is a JavaScript-based template engine used to generate dynamic web content. A security flaw allows an attacker who can control the content of a template to modify the underlying behavior of the server application. This can lead to the application crashing or, in some environments, allow the attacker to execute unauthorized commands on the server.
Technical details
A prototype pollution vulnerability exists in Velocity.js versions up to and including 2.1.5. The root cause is located in the #set path assignment logic within `/src/compile/set.ts`, where the engine performs assignments using arbitrary path keys without validation. An attacker can provide a malicious template containing a `#set` directive that targets sensitive keys like `__proto__`, `constructor`, or `prototype`. By polluting the global `Object.prototype`, an attacker can achieve denial of service (DoS) or remote code execution (RCE) depending on the server-side environment and how the application handles objects. As of the advisory date, no patched version is available.
Affected products
- shepherdwind velocityjs <= 2.1.5
Timeline
- 2026-05-06: disclosed: Vulnerability reported to the maintainer.
- 2026-05-09: advisory: GitHub Advisory published.