SB2026100660 - Multiple vulnerabilities in handlebars.js



SB2026100660 - Multiple vulnerabilities in handlebars.js

Published: October 6, 2026

Security Bulletin ID SB2026100660
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper Encoding or Escaping of Output (CVE-ID: N/A)

CWE-ID: CWE-116 - Improper Encoding or Escaping of Output

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary JavaScript in a victim's browser.

The vulnerability exists due to improper encoding or escaping of output in quotedString() in lib/handlebars/compiler/code-gen.js when precompiling attacker-controlled templates for direct embedding in HTML script elements. A remote attacker can supply a crafted template containing a closing script tag followed by malicious markup to execute arbitrary JavaScript in a victim's browser.

A victim must view the resulting HTML document. Ordinary server-side rendering and precompiled templates delivered as external JavaScript files are not affected.


2) Incomplete List of Disallowed Inputs (CVE-ID: N/A)

CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary JavaScript on the server.

The vulnerability exists due to an own-property check that bypasses the prototype-access deny list in the lookupProperty function when rendering attacker-controlled templates. A remote attacker can access the Function constructor through the own constructor property of Function.prototype and invoke it with attacker-controlled code to execute arbitrary JavaScript on the server.

Exploitation requires allowProtoMethodsByDefault to be set to true and an accessible function in the template context.


Remediation

Install update from vendor's website.