SB2026100660 - Multiple vulnerabilities in handlebars.js
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Improper Encoding or Escaping of Output (CVE-ID: N/A)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to improper encoding or escaping of output in quotedString() in lib/handlebars/compiler/code-gen.js when precompiling attacker-controlled templates for direct embedding in HTML script elements. A remote attacker can supply a crafted template containing a closing script tag followed by malicious markup to execute arbitrary JavaScript in a victim's browser.
A victim must view the resulting HTML document. Ordinary server-side rendering and precompiled templates delivered as external JavaScript files are not affected.
2) Incomplete List of Disallowed Inputs (CVE-ID: N/A)
CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript on the server.
The vulnerability exists due to an own-property check that bypasses the prototype-access deny list in the lookupProperty function when rendering attacker-controlled templates. A remote attacker can access the Function constructor through the own constructor property of Function.prototype and invoke it with attacker-controlled code to execute arbitrary JavaScript on the server.
Exploitation requires allowProtoMethodsByDefault to be set to true and an accessible function in the template context.
Remediation
Install update from vendor's website.