PatchSiren

shepherdwind CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL shepherdwind CVE published 2026-08-13

CVE-2026-73649

CVE-2026-73649 is a critical vulnerability in Velocity.js, a JavaScript implementation of the Apache Velocity template engine. The vulnerability allows an attacker to execute arbitrary shell commands, access environment variables, cloud credentials, and internal networks in the server process. This issue was caused by an incomplete fix for CVE-2026-44966, which only filtered constructor, __proto__, and pr [truncated]

HIGH shepherdwind CVE published 2026-05-26

CVE-2026-44966

A prototype pollution vulnerability in velocityjs ≤2.1.5 allows attackers to modify Object.prototype through malicious #set directives in Velocity templates. When applications render attacker-controlled templates, this can escalate to Denial of Service or Remote Code Execution depending on server environment configuration. The vulnerability stems from improper handling of property assignment during templa [truncated]