
🚨 High - Velocity.js Prototype Pollution (CVE-2026-44966) A prototype pollution vulnerability in Velocity.js exists within the processing of #set directives. By providing crafted template content, an attacker can modify Object.prototype via sensitive keys like __proto__. This can lead to application crashes (DoS) or be chained to achieve Remote Code Execution (RCE). 👉 Affected: velocityjs <= 2.1.5
Post summary
Velocity.js is impacted by CVE-2026-44966, a prototype pollution flaw that can be escalated to remote code execution or cause denial‑of‑service in versions ≤2.1.5.

