Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-106446: Handlebars can let attackers execute code on server

CVE-2026-106446 · published 3 days ago
Summary

Versions 4.0.0 through 4.7.10 of Handlebars let an attacker supply a crafted object instead of a template string, causing the compiler to embed malicious JavaScript that runs on the server. This can lead to the attacker taking control of the server process when the compiled template is used. Upgrade to Handlebars 4.7.10 or later to stop the risk; applications that only pass plain strings are not affected.

What to do
  • Update handlebars to version 4.7.10.
  • Update handlebars to version 3.0.8-aikido.1.
  • Update rootio @rootio/handlebars to version 3.0.8-root.io.1.
Affected software
Ecosystem VendorProductAffected versions
– handlebars-lang handlebars.js >= 4.0.0, < 4.7.10
Debian:12 debian node-handlebars All versions
Ubuntu:16.04:LTS canonical ruby-handlebars-assets All versions
Ubuntu:18.04:LTS canonical node-handlebars All versions
npm – handlebars >= 4.0.0, <= 4.7.9
>= 4.0.0, < 4.7.10
Fix: upgrade to 4.7.10
Root:npm – handlebars < 3.0.8-aikido.1
Fix: upgrade to 3.0.8-aikido.1
Root:npm rootio @rootio/handlebars < 3.0.8-root.io.1
Fix: upgrade to 3.0.8-root.io.1
Original advisory text
CVE-2026-106446 in handlebars - Patched by Root
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation introduced in version 4.7.9 for CVE-2026-33937. An attacker who can supply an object instead of a template string can place JavaScript expressions in unchecked values such as Program.blockParams.length, a non-PathExpression parameter depth, a non-string StringLiteral.value, or a non-string PathExpression.original. The compiler emits those values into generated JavaScript, causing code execution in the server process when compile output renders or wherever precompile output is loaded. Applications that pass only template strings are not affected. This issue is fixed in version 4.7.10.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-94Code Injection
CWE-843Type Confusion
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta