Junglewise Threat Intelligence

CVE-2026-73649: Velocity.js remote code execution via property-read to Function constructor

CVE-2026-73649 · Severity: low · CVSS 3.1 · Published 2026-07-24

Executive brief

Velocity.js is a templating engine that renders dynamic content from templates. A vulnerability allows attackers to execute arbitrary code on servers running applications that render untrusted Velocity templates by traversing the JavaScript prototype chain to access the Function constructor. This can lead to complete server compromise, including execution of system commands and theft of credentials.

Technical details

The vulnerability is a code injection flaw (CWE-94) in the property-read evaluation mechanism. A previous fix (GHSA-j658-c2gf-x6pq) added filtering to the #set directive assignment target in set.cjs, but the filtering was not applied to value expressions evaluated via getAttributes() in references.cjs. An attacker can chain property reads (e.g., $x.constructor.constructor) to reach the Function constructor and invoke it with arbitrary code. The attack requires no authentication and can be triggered by rendering any attacker-supplied template. A proof-of-concept demonstrates execution of shell commands via process.mainModule.require('child_process').execSync(). The vulnerability affects versions up to 2.1.6 and was fixed in version 2.1.7 via pull request #192.

Affected products

  • shepherdwind Velocity.js before 2.1.7

Timeline

  • 2026-07-24: disclosed
  • 2026-07-15: patched: Fix merged to master and released as v2.1.7

References