Incomplete List of Disallowed Inputs in handlebars.js - #VU153369

 

Incomplete List of Disallowed Inputs in handlebars.js - #VU153369

Published: October 6, 2026


Vulnerability identifier: #VU153369
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-184
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript on the server.

The vulnerability exists due to an own-property check that bypasses the prototype-access deny list in the lookupProperty function when rendering attacker-controlled templates. A remote attacker can access the Function constructor through the own constructor property of Function.prototype and invoke it with attacker-controlled code to execute arbitrary JavaScript on the server.

Exploitation requires allowProtoMethodsByDefault to be set to true and an accessible function in the template context.


Affected software

handlebars.js

Remediation

Install security update from vendor's website.

handlebars.js - update to 4.7.10

External References

Related Security Bulletins