Directory Traversal Vulnerability in Handlebars.java and handlebars-springmvc
CVE-2026-103088

7.5HIGH

Key Information:

Vendor

Jknack

Vendor
CVE Published:
30 September 2026

What is CVE-2026-103088?

The vulnerability allows attackers to conduct directory traversal attacks via crafted requests in applications using Handlebars.java versions before 4.5.5 and handlebars-springmvc 4.5.3 and 4.5.4. It occurs due to improper validation of template locations, where the template file is opened through a URL handler that decodes percent-encoded paths. This may enable attackers to access files outside of the configured template base directory by leveraging a percent-encoded traversal character sequence, compromising the security of the application.

Affected Version(s)

handlebars.java 4.5.3 < 4.5.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.