« Back to list

Handlebarsjs

Handlebarsjs Handlebars: vulnerabilities and CVEs

Handlebarsjs Handlebars has 10 published vulnerabilities, 6 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs10
Last 12 months6
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-33941High (8.2)0.22%—Mar 27, 2026
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled…
CVE-2026-33940High (8.1)0.79%—Mar 27, 2026
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all conditional guards in `resolvePartial()` and…
CVE-2026-33939High (7.5)0.76%—Mar 27, 2026
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`),…
CVE-2026-33938High (8.1)0.84%—Mar 27, 2026
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data context and is reachable and mutable…
CVE-2026-33937Critical (9.8)1.7%—Mar 27, 2026
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field…
CVE-2026-33916Medium (4.7)0.38%—Mar 27, 2026
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on…
CVE-2021-23383Critical (9.8)4.5%—May 4, 2021
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
CVE-2021-23369Critical (9.8)7.0%—Apr 12, 2021
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
CVE-2019-20922High (7.5)3.7%—Sep 30, 2020
Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to…
CVE-2019-20920High (8.1)3.2%—Sep 30, 2020
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript.…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application4
  2. T1059 Command and Scripting Interpreter3
  3. T1059.007 JavaScript1
  4. T1189 Drive-by Compromise1
  5. T1499.004 Application or System Exploitation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.