Prototype Access Vulnerability in Handlebars by Handlebars.js
CVE-2026-106445
9.2CRITICAL
What is CVE-2026-106445?
The Handlebars library allows users to create powerful semantic templates. A security vulnerability has been identified in versions from 4.0.0 to 4.7.10, affecting how the lookupProperty method handles prototype access. When an attacker exploits a controlled template with allowProtoMethodsByDefault enabled, they can access the Function.prototype constructor through a bypass, which could lead to the execution of attacker-controlled JavaScript under the application's privileges. This vulnerability has been addressed in version 4.7.10.
Affected Version(s)
handlebars.js >= 4.0.0, < 4.7.10
