Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2019-19919: Handlebars library versions allow attacker to run code

CVE-2019-19919 · published 1 day ago
Summary

Several Handlebars packages, including jaylinski/handlebars, bootstrap-wysihtml5-rails, handlebars.js, and Tenable SC, contain a flaw that could let a malicious user execute code on your server. This could lead to unauthorized actions or data exposure. Update to the latest patched releases of each affected package as soon as possible.

What to do
  • Update jaylinski handlebars to version 4.3.0.
  • Update jaylinski handlebars to version 3.0.8.
  • Update handlebars to version 3.0.8-aikido.1.
  • Update rootio @rootio/handlebars to version 3.0.8-root.io.1.
  • Update tenable tenable.sc to version 5.19.0 or later.
Affected software
Ecosystem VendorProductAffected versions
npm jaylinski handlebars >= 4.0.0, < 4.3.0
< 3.0.8
Fix: upgrade to 4.3.0
rubygems gonzalo rodríguez-baltanás díaz bootstrap-wysihtml5-rails >= 0.3.3.5, <= 0.3.3.8
– handlebars.js_project handlebars.js 1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
31 more version ranges
cpe:2.3:a:handlebars.js_project:handlebars.js:1.0.6:-:*:*:*:node.js:*:*
– tenable tenable.sc < 5.19.0
cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*
Root:npm – handlebars < 3.0.8-aikido.1
Fix: upgrade to 3.0.8-aikido.1
Root:npm rootio @rootio/handlebars < 3.0.8-root.io.1
Fix: upgrade to 3.0.8-root.io.1
Original advisory text
CVE-2019-19919 in handlebars - Patched by Root
Root has patched CVE-2019-19919 in the handlebars package for Root:npm. Multiple fixed versions available.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically (estimated)
  • Gives an attacker full control (estimated)
Severity
9.8 Critical
Exploitation
7% chance of attack within 30 days
Type
CWE-74Injection
CWE-1321Prototype Pollution
Timeline
Published8 Oct 2026
Updated9 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta