Node.js Process Crash in hbs View Engine 4.3.0 by Express
CVE-2026-87123
5.9MEDIUM
What is CVE-2026-87123?
The hbs view engine for Handlebars in version 4.3.0 is vulnerable to a process crash due to a TypeError that arises when using an async helper that resolves to a non-callable object with a truthy toHTML property. This can lead to uncaught exceptions during rendering, terminating the Node.js process and causing it to fail to respond. Users are advised to upgrade to hbs version 4.3.1 or later to mitigate this issue. The vulnerability can be triggered remotely through manipulated inputs, such as parsed JSON.
Affected Version(s)
hbs 4.3.0 < 4.3.1
hbs 4.3.1
