Code Injection in handlebars.js - CVE-2026-33938
Published: April 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to code injection through type confusion in the @partial-block handling and dynamic compilation fallback when processing a tampered @partial-block value during partial invocation. A remote attacker can overwrite @partial-block with a crafted Handlebars AST to execute arbitrary code.
The issue affects handlebars.js when templates can reach and mutate the data frame, and a subsequent {{> @partial-block}} causes the crafted AST to be compiled and executed in the server process.
Affected software
Storage Defender Copy Data Management
MongoDB Enterprise Advanced with IBM
Fedora
IBM App Connect Enterprise
nextcloud
How to mitigate CVE-2026-33938
Storage Defender Copy Data Management - update to 2.3.1.0
MongoDB Enterprise Advanced with IBM - update to 8.0.25
IBM App Connect Enterprise - addressed in versions 12.0.12.25, 13.0.7.1
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in handlebars.js
- Multiple vulnerabilities in IBM App Connect Enterprise
- Fedora 44 update for nextcloud
- Fedora 43 update for nextcloud
- Fedora EPEL 10.3 update for nextcloud
- Fedora EPEL 10.2 update for nextcloud
- Fedora 42 update for nextcloud
- Multiple vulnerabilities in IBM Storage Defender Copy Data Management
- Multiple vulnerabilities in MongoDB Enterprise Advanced with IBM