PT-2026-107182 · Unknown · Handlebars
CVE-2026-106446
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Handlebars versions 4.0.0 through 4.7.9
Description
Handlebars.compile() and Handlebars.precompile() functions accept pre-parsed AST (Abstract Syntax Tree) objects but only validate specific PathExpression, NumberLiteral, and BooleanLiteral values. This allows an attacker to bypass AST validation by providing an object instead of a template string. By inserting JavaScript expressions into unchecked values such as
Program.blockParams.length, a non-PathExpression parameter depth, a non-string StringLiteral.value, or a non-string PathExpression.original, the compiler emits these values into the generated JavaScript. This leads to code execution in the server process during the rendering of compile output or the loading of precompile output. Applications that exclusively use template strings are not affected.Recommendations
Update to version 4.7.10.
Exploit
Fix
Type Confusion
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Handlebars