Cross-Site Scripting Vulnerability in Handlebars by Handlebars.js
CVE-2026-106444
4.7MEDIUM
What is CVE-2026-106444?
A vulnerability in the Handlebars templating engine allows attackers to craft malicious template text that, when precompiled and directly embedded in inline script elements, can manipulate the HTML structure. This issue arises due to improper handling of user-controlled strings, leading to potential XSS attacks. Only specific scenarios involving direct inline script embedding are vulnerable, while other server-side rendering methods remain unaffected. The vulnerability has been resolved in Handlebars version 4.7.10.
Affected Version(s)
handlebars.js >= 4.0.0, < 4.7.10
