Cross-Site Scripting Vulnerability in Handlebars by Handlebars.js
CVE-2026-106444

4.7MEDIUM

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106444?

A vulnerability in the Handlebars templating engine allows attackers to craft malicious template text that, when precompiled and directly embedded in inline script elements, can manipulate the HTML structure. This issue arises due to improper handling of user-controlled strings, leading to potential XSS attacks. Only specific scenarios involving direct inline script embedding are vulnerable, while other server-side rendering methods remain unaffected. The vulnerability has been resolved in Handlebars version 4.7.10.

Affected Version(s)

handlebars.js >= 4.0.0, < 4.7.10

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.