« Volver al listado

CVE-2026-103088

Estado: AplazadaAlta (7.5)—

Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Aplicación web expuesta (AV:N, PR:N) permite traversal de directorio (CWE-24) para leer archivos fuera del directorio base mediante codificación percent-encoded en la ruta de template.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-103088",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-103088",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-30T17:13:35.282546Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "repo": "https://github.com/jknack/handlebars.java",
          "vendor": "jknack",
          "product": "handlebars.java",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.3",
              "lessThan": "4.5.5",
              "versionType": "maven"
            }
          ],
          "packageURL": "pkg:maven/com.github.jknack/handlebars-springmvc",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-30T02:16:57.203",
  "references": [
    {
      "url": "https://github.com/jknack/handlebars.java/commit/f6ae3979917d05bef07f00befb4013ef00503660",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/jknack/handlebars.java/releases/tag/v4.5.5",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/jknack/handlebars.java/security/advisories/GHSA-pvrx-3g7m-fpgv",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/jknack/handlebars.java/security/advisories/GHSA-pvrx-3g7m-fpgv",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-24"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory."
    }
  ],
  "lastModified": "2026-09-30T18:18:15.493",
  "sourceIdentifier": "cve@mitre.org"
}