JavaScript Code Execution Vulnerability in Handlebars by Handlebars-lang
CVE-2026-106446
What is CVE-2026-106446?
The Handlebars template engine is susceptible to a vulnerability where untrusted input can pass through to the compiler without adequate validation, leading to potential remote code execution. This occurs from versions 4.0.0 to 4.7.10, where attackers can exploit the ability of Handlebars.compile() and Handlebars.precompile() to accept pre-parsed AST (Abstract Syntax Tree) objects. By providing an object instead of a template string, an attacker can bypass the introduced validations and inject arbitrary JavaScript expressions into certain parameters. This flaw can cause dangerous code execution on the server when the compiled output is executed. Users are encouraged to upgrade to version 4.7.10 or later to mitigate this risk.
Affected Version(s)
handlebars.js >= 4.0.0, < 4.7.10
