PT-2026-102972 · Unknown+1 · Handlebars.Java+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Handlebars.java versions prior to 4.5.5
Description
An issue allows directory traversal when using a Spring MVC application with a
file: template prefix and a request-derived view name. In certain versions, template locations are validated as raw percent-encoded strings, but the template file is opened via a URL handler that percent-decodes the path. This allows a percent-encoded traversal sequence, such as %2e%2e/, to bypass the view-resolver check and the loader-side containment, enabling the reading of files outside the configured template base directory.Recommendations
Update Handlebars.java to version 4.5.5 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Handlebars.Java
Spring Mvc