CVE-2026-73649 is a critical vulnerability in Velocity.js, a JavaScript implementation of the Apache Velocity template engine. The vulnerability allows an attacker to execute arbitrary shell commands, access environment variables, cloud credentials, and internal networks in the server process. This issue was caused by an incomplete fix for CVE-2026-44966, which only filtered constructor, __proto__, and pr [truncated]
A prototype pollution vulnerability in velocityjs ≤2.1.5 allows attackers to modify Object.prototype through malicious #set directives in Velocity templates. When applications render attacker-controlled templates, this can escalate to Denial of Service or Remote Code Execution depending on server environment configuration. The vulnerability stems from improper handling of property assignment during templa [truncated]