


Perceptive Security
SOC/SIEM Consultancy

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context …
Published:
26 maart 2026 om 23:00:00
Alert date:
27 maart 2026 om 23:03:46
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A critical vulnerability in Handlebars versions 4.0.0 through 4.7.8 allows attackers to execute arbitrary commands on the server through crafted objects in template context. The vulnerability bypasses conditional guards in resolvePartial() and causes invokePartial() to return undefined, leading to compilation of malicious Handlebars AST containing injected code. The attack requires adversary control over values returned by dynamic partial lookups. Fixed in version 4.7.9 with workarounds available including using runtime-only builds, sanitizing context data, and avoiding dynamic partial lookups with user-controlled data.
Technical details
Mitigation steps:
Affected products:
Handlebars
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33940
https://github.com/handlebars-lang/handlebars.js/commit/68d8df5a88e0a26fe9e6084c5c6aaebe67b07da2
https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-xhpv-hc6g-r9c6
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
