{"id":"GHSA-j658-c2gf-x6pq","summary":"Velocity.js has a Prototype Pollution vulnerability through #set path assignment","details":"### Summary\nA prototype pollution vulnerability was discovered in Velocity.js \u003c= 2.1.5. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it is possible to modify Object.prototype, potentially leading to Denial of Service (DoS) or Remote Code Execution (RCE) depending on the server environment.\n\n### Details\nThe root cause is located in the #set path assignment logic within the source code:\n- File: /src/compile/set.ts \n- Issue: The engine accepts arbitrary path keys and performs assignments using the logic `(baseRef as Record\u003cstring, unknown\u003e)[key] = val`.\n\n\nBecause there is no validation or filtering to block sensitive keys such as \\_\\_proto\\_\\_, constructor, or prototype, an attacker can traverse the prototype chain and pollute the global Object.prototype.\n\n### PoC\n```javascript\nconst {render} = require('velocityjs');\ndelete Object.prototype.polluted;\nconsole.log({}.polluted); // \"\"\nrender('#set($__proto__.polluted = \"hacked\")', {});\nconsole.log({}.polluted); // \"hacked\"\ndelete Object.prototype.polluted;\n```\n\n### Impact\n- Vulnerability Type: Prototype Pollution\n- Who is impacted: Any application that renders Velocity templates where the template content can be influenced or controlled by untrusted users.\n- Severity: High. Prototype pollution can often be used to bypass security controls, cause application crashes (DoS), or be chained with other vulnerabilities to achieve code execution.","aliases":["CVE-2026-44966"],"modified":"2026-06-08T23:45:16.063373921Z","published":"2026-05-09T00:40:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-09T00:40:16Z","nvd_published_at":"2026-05-26T22:16:43Z","cwe_ids":["CWE-1321"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/shepherdwind/velocity.js/security/advisories/GHSA-j658-c2gf-x6pq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44966"},{"type":"PACKAGE","url":"https://github.com/shepherdwind/velocity.js"}],"affected":[{"package":{"name":"velocityjs","ecosystem":"npm","purl":"pkg:npm/velocityjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.1.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-j658-c2gf-x6pq/GHSA-j658-c2gf-x6pq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}]}