CVE-2026-73649 | shepherdwind Velocity.js up to 2.1.6 Property-Read Expressions references.ts getReferences os command injection
A vulnerability, which was classified as critical, was found in shepherdwind Velocity.js up to 2.1.6. This issue affects the function getReferences of the file src/compile/references.ts of the component Property-Read Expressions. Executing a manipulation can lead to os command injection.
The identification of this vulnerability is CVE-2026-73649. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More