Potential Remote Code Execution in velocityjs v2.1.6: Early Warning
An early warning has been issued regarding a potential Remote Code Execution (RCE) vulnerability in velocityjs version 2.1.6. This vulnerability reportedly allows arbitrary code execution on servers rendering attacker-controlled Velocity templates.
What happened
According to the GitHub Security Advisory GHSA-7gfh-x38p-prh3, velocityjs version 2.1.6 appears to contain a critical vulnerability that bypasses a previous fix for a prototype pollution issue (tracked as GHSA-j658-c2gf-x6pq). This bypass enables remote code execution via property-read to the Function constructor.
The vulnerability is under investigation, and it is recommended that any application utilizing server-side rendering of Velocity templates be reviewed for potential exposure. Specifically, applications that render templates controlled by attackers may be at risk.
At this time, a patched version of velocityjs is not yet available. Engineers are advised to monitor updates from the primary sources and prepare to upgrade once a fix is released. Further details and confirmations should be sought from the GitHub Advisory Database entries GHSA-7gfh-x38p-prh3 and GHSA-j658-c2gf-x6pq.
How 0Day mitigates this
velocityjs is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.