VYPR

npm package

velocityjs

pkg:npm/velocityjs

Vulnerabilities (1)

  • CVE-2026-44966HigMay 26, 2026
    affected <= 2.1.5

    Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a