Improper Encoding or Escaping of Output in handlebars.js - #VU153368
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to improper encoding or escaping of output in quotedString() in lib/handlebars/compiler/code-gen.js when precompiling attacker-controlled templates for direct embedding in HTML script elements. A remote attacker can supply a crafted template containing a closing script tag followed by malicious markup to execute arbitrary JavaScript in a victim's browser.
A victim must view the resulting HTML document. Ordinary server-side rendering and precompiled templates delivered as external JavaScript files are not affected.