Directory Traversal Vulnerability in Handlebars.java and handlebars-springmvc
CVE-2026-103088
7.5HIGH
What is CVE-2026-103088?
The vulnerability allows attackers to conduct directory traversal attacks via crafted requests in applications using Handlebars.java versions before 4.5.5 and handlebars-springmvc 4.5.3 and 4.5.4. It occurs due to improper validation of template locations, where the template file is opened through a URL handler that decodes percent-encoded paths. This may enable attackers to access files outside of the configured template base directory by leveraging a percent-encoded traversal character sequence, compromising the security of the application.
Affected Version(s)
handlebars.java 4.5.3 < 4.5.5
