Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-106445: Handlebars templates may execute attacker-controlled JavaScript
CVE-2026-106445 · published 3 days ago
Summary
Versions of Handlebars from 4.0.0 to 4.7.9 allow a specially crafted template to bypass safety checks and run arbitrary JavaScript on the server. This can let an attacker execute code with the same rights as your application. Upgrade Handlebars to version 4.7.10 or later to stop the issue.
What to do
- Update handlebars to version 4.7.10.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | handlebars-lang | handlebars.js | >= 4.0.0, < 4.7.10 |
| Debian:12 | debian | node-handlebars | All versions |
| Ubuntu:18.04:LTS | canonical | node-handlebars | All versions |
| npm | – | handlebars |
>= 4.0.0, <= 4.7.9 >= 4.0.0, < 4.7.10 Fix: upgrade to 4.7.10
|
Original advisory text
Handlebars: JavaScript Injection via Own Property Check Bypass
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-1064... Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-106445 Vendor Advisory
- https://github.com/advisories/GHSA-p8wg-vrv2-v86f
- https://github.com/handlebars-lang/handlebars.js Product
- https://nvd.nist.gov/vuln/detail/CVE-2026-106445 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-106445 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-106445 Third Party Advisory
- https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-p8wg-v...
- https://github.com/handlebars-lang/handlebars.js/pull/2185
- https://github.com/handlebars-lang/handlebars.js/commit/ceec388abe1d1aac8f636986...
- https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.9
Critical
Type
CWE-184Incomplete List of Disallowed Inputs
CWE-1289Improper Validation of Unsafe Equivalence in Input
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-106445 · NVD
CVE-2026-106445 · MITRE
DEBIAN-CVE-2026-106445 · OSV
CVE-2026-106445 · OSV
GHSA-p8wg-vrv2-v86f · GHSA
UBUNTU-CVE-2026-106445 · OSV
GHSA-p8wg-vrv2-v86f · OSV
Track software like this
Free during beta