Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.69% | — | Handlebars.javaAI | 30/9/2026 | 30/9/2026 | Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application… | |
| Aplazada | Alta (7.5) | 0.69% | — | Jknack Handlebars.javaAIJknack Handlebars-springmvcAI | 20/8/2026 | 18/9/2026 | Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment validation used by other URL-based loaders. In… | |
| Pendiente de análisis | Alta (7.5) | 0.53% | — | Handlebars.javaAI | 8/7/2026 | 10/7/2026 | Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handlebars.compile() using FileTemplateLoader or ClassPathTemplateLoader are vulnerable to path traversal, allowing arbitrary file read through template names derived from URL… | |
| Modificada | Alta (8.2) | 0.22% | — | Handlebarsjs Handlebars | 27/3/2026 | 4/9/2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without… | |
| Modificada | Alta (8.1) | 0.79% | — | Handlebarsjs Handlebars | 27/3/2026 | 4/9/2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all conditional guards in `resolvePartial()` and cause `invokePartial()` to return `undefined`. The Handlebars runtime then treats the unresolved… | |
| Modificada | Alta (7.5) | 0.76% | — | Handlebarsjs Handlebars | 27/3/2026 | 4/9/2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the compiled template calls `lookupProperty(decorators, "n")`, which returns `undefined`. The… | |
| Modificada | Alta (8.1) | 0.84% | — | Handlebarsjs Handlebars | 27/3/2026 | 4/9/2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data context and is reachable and mutable from within a template via helpers that accept arbitrary objects. When a helper overwrites… | |
| Modificada | Crítica (9.8) | 1.7% | — | Handlebarsjs Handlebars | 27/3/2026 | 4/9/2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLiteral` AST node is emitted directly into the generated JavaScript without quoting or… | |
| Analizada | Media (4.7) | 0.38% | — | Handlebarsjs Handlebars | 27/3/2026 | 17/6/2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been… | |
| Aplazada | Alta (8.2) | 0.43% | — | Felixriddle Dev-jobs-handlebarsAI | 16/10/2025 | 17/6/2026 | FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/load-balancer that forwards the header unchanged) can cause reset links to point… | |
| Modificada | Alta (8.6) | 16% | — | Express Handlebars Project Express Handlebars | 14/5/2021 | 17/6/2026 | Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications. This potential vulnerability is… | |
| Modificada | Media (6.8) | 1.3% | — | Express Handlebars Project Express Handlebars | 14/5/2021 | 17/6/2026 | express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications. This potential vulnerability is somewhat… | |
| Modificada | Crítica (9.8) | 4.5% | — | Handlebarsjs HandlebarsNetapp E-series Performance Analyzer | 4/5/2021 | 17/6/2026 | The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source. | |
| Modificada | Crítica (9.8) | 7.0% | — | Handlebarsjs Handlebars | 12/4/2021 | 17/6/2026 | The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source. | |
| Modificada | Alta (7.5) | 3.7% | — | Handlebarsjs Handlebars | 30/9/2020 | 17/6/2026 | Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources. | |
| Modificada | Alta (8.1) | 3.2% | — | Handlebarsjs Handlebars | 30/9/2020 | 17/6/2026 | Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's… | |
| Modificada | Crítica (9.8) | 7.1% | — | Handlebars.js Project Handlebars.jsTenable.sc | 20/12/2019 | 17/6/2026 | Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads. | |
| Modificada | Media (6.1) | 2.6% | — | Handlebars.js Project Handlebars.js | 23/1/2017 | 17/6/2026 | The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted. |