top of page
perceptive_background_267k.jpg

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handlebars.compil…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 21:04:14

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

CVE-2026-55760 is a path traversal vulnerability in Handlebars.java, a Java-based logic-less Mustache template engine. Versions prior to 4.5.2 are affected. The vulnerability exists when applications pass user-controlled input to Handlebars.compile() using FileTemplateLoader or ClassPathTemplateLoader. Attackers can exploit this to perform arbitrary file reads on the host system by crafting malicious template names derived from URL path parameters, request parameters, or other user-controlled sources. This poses a significant risk to applications that dynamically compile templates based on user input. The vulnerability has been patched in version 4.5.2 of Handlebars.java. Developers are strongly advised to upgrade to the fixed version to mitigate exposure to unauthorized file access.

Technical details

Mitigation steps:

Affected products:

Handlebars.java < 4.5.2

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page