TL;DR
Maintainers of Handlebars.js have patched two critical flaws that can lead to remote code execution. Each Handlebars.js vulnerability lets an attacker run arbitrary JavaScript on a Node.js server. Both the technical details and proof-of-concept exploit code are now public, and the library sees more than 172 million downloads each month.
- Product: handlebars-lang handlebars.js
- Vulnerabilities: 2 flaws (CVE-2026-106445, CVE-2026-106446)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams)
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-106446 | 9.8 | CWE-94 | Not exploited |
| CVE-2026-106445 | 9.2 | Handlebars: JavaScript Injection via Own Property Check Bypass | Not exploited |
Turn matching CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysWhy It Matters
Handlebars.js is a widely used templating engine for JavaScript. The npm package records over 172.6 million downloads monthly, by the project’s own count. That reach makes any server-side flaw a broad concern.
Crucially, the write-ups and the exploit code are both out in the open. The two GitHub advisories, GHSA-p8wg-vrv2-v86f advisory and GHSA-8r5x-fm3f-whwj advisory, document each bug in full. Because the details are public, defenders should treat patching as urgent. Even so, the advisories report no exploitation in the wild.
How the Attacks Work
Deny List Bypass (CVE-2026-106445)
The first flaw carries a CVSS score of 9.2. Handlebars keeps a deny list meant to block access to dangerous properties such as constructor. However, the check can be skipped. The advisory explains that Handlebars “can expose the Function constructor despite its prototype-access deny list.”
In short, a lookup reaches a property that the deny list never evaluates. That path returns the Function constructor, which an attacker can use to build and run code. The bug applies when an app renders a controlled template with the allowProtoMethodsByDefault option turned on.
AST Type Confusion (CVE-2026-106446)
The second Handlebars.js vulnerability rates 9.8. It affects the compile() and precompile() functions, which accept a pre-parsed template tree as well as a string. Validation added in version 4.7.9 checks only some nodes in that tree.
As a result, the compiler writes other values into the generated code unchecked. Per the advisory, an untrusted object “can carry arbitrary JavaScript.” A common trigger is passing a field from a JSON request body straight into compile(). This issue bypasses an earlier fix tracked as CVE-2026-33937. Apps that only ever pass template strings are not affected.
Affected Versions
Both flaws affect the same range of releases:
- Affected: Handlebars 4.0.0 through 4.7.9
- Patched: Handlebars 4.7.10
Patch and Mitigation Steps
Upgrade to Handlebars 4.7.10 without delay. That release closes both injection paths and resolves each Handlebars.js vulnerability. Since the details and PoC are public, the patch is the one durable fix.
If you cannot update at once, apply the vendor workarounds. First, never set allowProtoMethodsByDefault to true for untrusted templates. Next, check that any value passed to compile() is a string, not an object. Finally, use the runtime-only build on servers where templates are pre-compiled at build time.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!