top of page
perceptive_background_267k.jpg

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context …

Published:

26 maart 2026 om 23:00:00

Alert date:

27 maart 2026 om 23:03:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

A critical vulnerability in Handlebars versions 4.0.0 through 4.7.8 allows attackers to execute arbitrary commands on the server through crafted objects in template context. The vulnerability bypasses conditional guards in resolvePartial() and causes invokePartial() to return undefined, leading to compilation of malicious Handlebars AST containing injected code. The attack requires adversary control over values returned by dynamic partial lookups. Fixed in version 4.7.9 with workarounds available including using runtime-only builds, sanitizing context data, and avoiding dynamic partial lookups with user-controlled data.

Technical details

Mitigation steps:

Affected products:

Handlebars

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page