


Perceptive Security
SOC/SIEM Consultancy

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handlebars.compil…
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 21:04:14
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
CVE-2026-55760 is a path traversal vulnerability in Handlebars.java, a Java-based logic-less Mustache template engine. Versions prior to 4.5.2 are affected. The vulnerability exists when applications pass user-controlled input to Handlebars.compile() using FileTemplateLoader or ClassPathTemplateLoader. Attackers can exploit this to perform arbitrary file reads on the host system by crafting malicious template names derived from URL path parameters, request parameters, or other user-controlled sources. This poses a significant risk to applications that dynamically compile templates based on user input. The vulnerability has been patched in version 4.5.2 of Handlebars.java. Developers are strongly advised to upgrade to the fixed version to mitigate exposure to unauthorized file access.
Technical details
Mitigation steps:
Affected products:
Handlebars.java < 4.5.2
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55760
https://github.com/jknack/handlebars.java/commit/d177cdee8b750385ca7a0d0f89f2d4be73e28f4e
https://github.com/jknack/handlebars.java/releases/tag/v4.5.2
https://github.com/jknack/handlebars.java/security/advisories/GHSA-r4gv-qr8j-p3pg
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
