Node.js Process Crash in hbs View Engine 4.3.0 by Express
CVE-2026-87123

5.9MEDIUM

Key Information:

Vendor

Hbs

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-87123?

The hbs view engine for Handlebars in version 4.3.0 is vulnerable to a process crash due to a TypeError that arises when using an async helper that resolves to a non-callable object with a truthy toHTML property. This can lead to uncaught exceptions during rendering, terminating the Node.js process and causing it to fail to respond. Users are advised to upgrade to hbs version 4.3.1 or later to mitigate this issue. The vulnerability can be triggered remotely through manipulated inputs, such as parsed JSON.

Affected Version(s)

hbs 4.3.0 < 4.3.1

hbs 4.3.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mfdebian
UlisesGascon
bjohansebas
official-burak
.