JavaScript Code Execution Vulnerability in Handlebars by Handlebars-lang
CVE-2026-106446

9.8CRITICAL

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106446?

The Handlebars template engine is susceptible to a vulnerability where untrusted input can pass through to the compiler without adequate validation, leading to potential remote code execution. This occurs from versions 4.0.0 to 4.7.10, where attackers can exploit the ability of Handlebars.compile() and Handlebars.precompile() to accept pre-parsed AST (Abstract Syntax Tree) objects. By providing an object instead of a template string, an attacker can bypass the introduced validations and inject arbitrary JavaScript expressions into certain parameters. This flaw can cause dangerous code execution on the server when the compiled output is executed. Users are encouraged to upgrade to version 4.7.10 or later to mitigate this risk.

Affected Version(s)

handlebars.js >= 4.0.0, < 4.7.10

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.