Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2019-19919: Handlebars library versions allow attacker to run code
CVE-2019-19919 · published 1 day ago
Summary
Several Handlebars packages, including jaylinski/handlebars, bootstrap-wysihtml5-rails, handlebars.js, and Tenable SC, contain a flaw that could let a malicious user execute code on your server. This could lead to unauthorized actions or data exposure. Update to the latest patched releases of each affected package as soon as possible.
What to do
- Update jaylinski handlebars to version 4.3.0.
- Update jaylinski handlebars to version 3.0.8.
- Update handlebars to version 3.0.8-aikido.1.
- Update rootio @rootio/handlebars to version 3.0.8-root.io.1.
- Update tenable tenable.sc to version 5.19.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | jaylinski | handlebars |
>= 4.0.0, < 4.3.0 < 3.0.8 Fix: upgrade to 4.3.0
|
| rubygems | gonzalo rodríguez-baltanás díaz | bootstrap-wysihtml5-rails | >= 0.3.3.5, <= 0.3.3.8 |
| – | handlebars.js_project | handlebars.js |
1.0.6 1.0.7 1.0.8 1.0.9 1.0.10 1.0.11 1.0.12 1.1.0 1.1.1 1.1.2 1.2.0 1.2.1 31 more version ranges
cpe:2.3:a:handlebars.js_project:handlebars.js:1.0.6:-:*:*:*:node.js:*:* |
| – | tenable | tenable.sc |
< 5.19.0 cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:* |
| Root:npm | – | handlebars |
< 3.0.8-aikido.1 Fix: upgrade to 3.0.8-aikido.1
|
| Root:npm | rootio | @rootio/handlebars |
< 3.0.8-root.io.1 Fix: upgrade to 3.0.8-root.io.1
|
Original advisory text
CVE-2019-19919 in handlebars - Patched by Root
Root has patched CVE-2019-19919 in the handlebars package for Root:npm. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-19919
- https://github.com/wycats/handlebars.js/issues/1558
- https://github.com/wycats/handlebars.js/commit/2078c727c627f25d4a149962f05c1e069...
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19919
- https://www.tenable.com/security/tns-2021-14
- https://github.com/handlebars-lang/handlebars.js/commit/156061eb7707575293613d7f...
- https://github.com/handlebars-lang/handlebars.js/commit/90ad8d97ad2933852fb83fcc...
- https://github.com/Nerian/bootstrap-wysihtml5-rails/blob/master/vendor/assets/ja...
- https://github.com/Nerian/bootstrap-wysihtml5-rails/tree/master/vendor/assets/ja...
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/bootstrap-wysihtml5...
- https://github.com/advisories/GHSA-w457-6q6x-cgp9
- https://www.npmjs.com/advisories/1164 Third Party Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically (estimated)
- Gives an attacker full control (estimated)
Type
CWE-74Injection
CWE-1321Prototype Pollution
Timeline
Published8 Oct 2026
Updated9 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta