Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-73649
  • github.com/shepherdwind/velocity.js
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) 13 Aug
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-44966
  • github.com/shepherdwind/velocity.js
Velocity.js: Prototype Pollution in #set path assignment 26 May
  • No fix available
  • Severity - 8.3 (High)