PT-2026-107182 · Unknown · Handlebars

CVE-2026-106446

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Handlebars versions 4.0.0 through 4.7.9
Description Handlebars.compile() and Handlebars.precompile() functions accept pre-parsed AST (Abstract Syntax Tree) objects but only validate specific PathExpression, NumberLiteral, and BooleanLiteral values. This allows an attacker to bypass AST validation by providing an object instead of a template string. By inserting JavaScript expressions into unchecked values such as Program.blockParams.length, a non-PathExpression parameter depth, a non-string StringLiteral.value, or a non-string PathExpression.original, the compiler emits these values into the generated JavaScript. This leads to code execution in the server process during the rendering of compile output or the loading of precompile output. Applications that exclusively use template strings are not affected.
Recommendations Update to version 4.7.10.

Exploit

Fix

Type Confusion

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106446

Affected Products

Handlebars