CRITICAL9.8npm
GHSA-7gfh-x38p-prh3· CVE-2026-73649Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Modified: 8/13/2026
package
pkg:npm/velocityjs
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Modified: 8/13/2026
Velocity.js has a Prototype Pollution vulnerability through #set path assignment
Modified: 6/8/2026