Incomplete List of Disallowed Inputs in handlebars.js - #VU153369
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript on the server.
The vulnerability exists due to an own-property check that bypasses the prototype-access deny list in the lookupProperty function when rendering attacker-controlled templates. A remote attacker can access the Function constructor through the own constructor property of Function.prototype and invoke it with attacker-controlled code to execute arbitrary JavaScript on the server.
Exploitation requires allowProtoMethodsByDefault to be set to true and an accessible function in the template context.