CRITICALnpm →
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Affected packages
- velocityjs
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/shepherdwind/velocity.js/security/advisories/GHSA-7gfh-x38p-prh3
- https://github.com/shepherdwind/velocity.js/pull/192
- https://github.com/shepherdwind/velocity.js/commit/f8e47a6c4607249b9c967d3a1ced959b4dd64dba
- https://github.com/shepherdwind/velocity.js
- https://github.com/shepherdwind/velocity.js/releases/tag/v2.1.7
Structured record: https://osv.dev/vulnerability/GHSA-7gfh-x38p-prh3
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta