๐Ÿ” CVE Alert

CVE-2026-106445

UNKNOWN 0.0

Handlebars: JavaScript Injection via Own Property Check Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.

CWE CWE-184 CWE-1289
Vendor handlebars-lang
Product handlebars.js
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for handlebars-lang handlebars.js

Be the first to know when new unknown vulnerabilities affecting handlebars-lang handlebars.js are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

handlebars-lang / handlebars.js
>= 4.0.0, < 4.7.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-p8wg-vrv2-v86f github.com: https://github.com/handlebars-lang/handlebars.js/pull/2185 github.com: https://github.com/handlebars-lang/handlebars.js/commit/ceec388abe1d1aac8f6369860d5f390fa71ef4fa github.com: https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10