CVE-2026-16231
hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after rendering hbs substitutes the placeholder with the raw callback return value without escaping it, across the cached, uncached, and layout render paths.
Leer descripción completaMostrar menos
An application that passes attacker-influenced data, for example user-supplied content from a database, into an async helper callback can therefore have arbitrary HTML and JavaScript injected into the server-rendered page, resulting in stored or reflected cross-site scripting. Versions 2.1.0 through 4.2.1 are affected, and the issue is fixed in 4.3.0, which HTML-escapes async helper output. Applications that intentionally emit raw HTML from an async helper can opt in explicitly with hbs.SafeString. Users should upgrade to 4.3.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1189Drive-by Compromiseinitial access95 % - Impacto principal
T1059.007JavaScriptexecution90 %
XSS reflejado/almacenado por bypass de sanitización en async helpers de hbs, UI:R confirma interacción. CWE-79 y inyección de JavaScript en página renderizada.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-16231",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-16231",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-25T19:47:24.248925Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"affectedData": [
{
"vendor": "hbs",
"product": "hbs",
"versions": [
{
"status": "affected",
"version": "2.1.0",
"lessThan": "4.3.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.3.0",
"versionType": "semver"
}
],
"packageURL": "pkg:npm/hbs",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-25T10:18:04.080",
"references": [
{
"url": "https://cna.openjsf.org/security-advisories.html",
"tags": [
"Vendor Advisory"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
},
{
"url": "https://github.com/pillarjs/hbs/security/advisories/GHSA-rg36-rxv9-2m9q",
"tags": [
"Vendor Advisory"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after rendering hbs substitutes the placeholder with the raw callback return value without escaping it, across the cached, uncached, and layout render paths. An application that passes attacker-influenced data, for example user-supplied content from a database, into an async helper callback can therefore have arbitrary HTML and JavaScript injected into the server-rendered page, resulting in stored or reflected cross-site scripting. Versions 2.1.0 through 4.2.1 are affected, and the issue is fixed in 4.3.0, which HTML-escapes async helper output. Applications that intentionally emit raw HTML from an async helper can opt in explicitly with hbs.SafeString. Users should upgrade to 4.3.0."
},
{
"lang": "es",
"value": "hbs es un motor de vistas de Express que envuelve Handlebars. Su API registerAsyncHelper omite el escape automático de HTML de Handlebars: un ayudante asíncrono devuelve un marcador de posición opaco durante la primera pasada de renderizado, por lo que la expresión de doble llave escapa solo el marcador de posición, y después de renderizar hbs sustituye el marcador de posición con el valor de retorno de la devolución de llamada sin procesar sin escaparlo, a través de las rutas de renderizado en caché, sin caché y de diseño. Una aplicación que pasa datos influenciados por el atacante, por ejemplo contenido proporcionado por el usuario de una base de datos, a una devolución de llamada de ayudante asíncrono puede, por lo tanto, tener HTML y JavaScript arbitrarios inyectados en la página renderizada por el servidor, lo que resulta en cross-site scripting almacenado o reflejado. Las versiones 2.1.0 a 4.2.1 están afectadas, y el problema está solucionado en la 4.3.0, que escapa el HTML de la salida del ayudante asíncrono. Las aplicaciones que emiten intencionalmente HTML sin procesar desde un ayudante asíncrono pueden optar explícitamente con hbs.SafeString. Los usuarios deben actualizar a la 4.3.0."
}
],
"lastModified": "2026-09-28T23:10:00.143",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hbs_project:hbs:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "185D8222-1F3D-4CA4-8D30-2F45910A4B7B",
"versionEndExcluding": "4.3.0",
"versionStartIncluding": "2.1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb"
}