Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-106446: Handlebars can let attackers execute code on server
CVE-2026-106446 · published 3 days ago
Summary
Versions 4.0.0 through 4.7.10 of Handlebars let an attacker supply a crafted object instead of a template string, causing the compiler to embed malicious JavaScript that runs on the server. This can lead to the attacker taking control of the server process when the compiled template is used. Upgrade to Handlebars 4.7.10 or later to stop the risk; applications that only pass plain strings are not affected.
What to do
- Update handlebars to version 4.7.10.
- Update handlebars to version 3.0.8-aikido.1.
- Update rootio @rootio/handlebars to version 3.0.8-root.io.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | handlebars-lang | handlebars.js | >= 4.0.0, < 4.7.10 |
| Debian:12 | debian | node-handlebars | All versions |
| Ubuntu:16.04:LTS | canonical | ruby-handlebars-assets | All versions |
| Ubuntu:18.04:LTS | canonical | node-handlebars | All versions |
| npm | – | handlebars |
>= 4.0.0, <= 4.7.9 >= 4.0.0, < 4.7.10 Fix: upgrade to 4.7.10
|
| Root:npm | – | handlebars |
< 3.0.8-aikido.1 Fix: upgrade to 3.0.8-aikido.1
|
| Root:npm | rootio | @rootio/handlebars |
< 3.0.8-root.io.1 Fix: upgrade to 3.0.8-root.io.1
|
Original advisory text
CVE-2026-106446 in handlebars - Patched by Root
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation introduced in version 4.7.9 for CVE-2026-33937. An attacker who can supply an object instead of a template string can place JavaScript expressions in unchecked values such as Program.blockParams.length, a non-PathExpression parameter depth, a non-string StringLiteral.value, or a non-string PathExpression.original. The compiler emits those values into generated JavaScript, causing code execution in the server process when compile output renders or wherever precompile output is loaded. Applications that pass only template strings are not affected. This issue is fixed in version 4.7.10.
References
- https://security-tracker.debian.org/tracker/CVE-2026-106446 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-106446 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-106446 Third Party Advisory
- https://github.com/advisories/GHSA-8r5x-fm3f-whwj
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-1064... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-106446 Vendor Advisory
- https://github.com/handlebars-lang/handlebars.js Product
- https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-8r5x-f... Third Party Advisory
- https://github.com/handlebars-lang/handlebars.js/pull/2185 Third Party Advisory
- https://github.com/handlebars-lang/handlebars.js/commit/703fdcc5fd6cc8d1cc0c33cc... URL
- https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10 URL
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-94Code Injection
CWE-843Type Confusion
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-106446 · NVD
CVE-2026-106446 · MITRE
DEBIAN-CVE-2026-106446 · OSV
UBUNTU-CVE-2026-106446 · OSV
GHSA-8r5x-fm3f-whwj · GHSA
CVE-2026-106446 · OSV
GHSA-8r5x-fm3f-whwj · OSV
Track software like this
Free during beta