---
id: CVE-2019-20920
title: >-
  Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code
  Execution
summary: >-
  Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code
  Execution. The lookup helper fails to properly validate templates, allowing
  attackers to submit templates that execute arbitrary JavaScript. This can be
  used to…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L'
cwe:
  - CWE-94
vendor: handlebarsjs
product: handlebars
affected:
  - handlebars < 3.0.8
  - 'handlebars >= 4.0.0, < 4.5.3'
patched:
  - handlebars 4.5.3
published: '2020-09-30'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:54.603'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-20920'
references:
  - url: 'https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478'
    label: cve@mitre.org
  - url: 'https://www.npmjs.com/advisories/1316'
    label: cve@mitre.org
  - url: 'https://www.npmjs.com/advisories/1324'
    label: cve@mitre.org
  - url: 'https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.npmjs.com/advisories/1316'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.npmjs.com/advisories/1324'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.03193
epssPercentile: 0.87727
ingestedAt: '2026-10-08T23:16:47.308Z'
---

## Overview

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

## Affected

- `handlebars < 3.0.8`
- `handlebars >= 4.0.0, < 4.5.3`

## Remediation

Upgrade past the affected range:

- `handlebars 4.5.3`
