---
id: CVE-2021-23369
title: >-
  The package handlebars before 4.7.7 are vulnerable to Remote Code Execution
  (RCE) when selecting certain compiling options to compile templates coming
  from an untrusted source.
summary: >-
  The package handlebars before 4.7.7 are vulnerable to Remote Code Execution
  (RCE) when selecting certain compiling options to compile templates coming
  from an untrusted source.
severity: medium
cvss: 5.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'
vendor: handlebarsjs
product: handlebars
affected:
  - handlebars < 4.7.7
patched:
  - handlebars 4.7.7
published: '2021-04-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:07.613'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-23369'
references:
  - url: >-
      https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321f04afdbae608e8fea8
    label: report@snyk.io
  - url: >-
      https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427
    label: report@snyk.io
  - url: 'https://security.netapp.com/advisory/ntap-20210604-0008/'
    label: report@snyk.io
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074950'
    label: report@snyk.io
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074951'
    label: report@snyk.io
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074952'
    label: report@snyk.io
  - url: 'https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767'
    label: report@snyk.io
  - url: >-
      https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321f04afdbae608e8fea8
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210604-0008/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074950'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074951'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074952'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.07028
epssPercentile: 0.94023
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/fazilbaig1/CVE-2021-23369'
    - 'https://github.com/dinhvaren/cve-2021-23369'
  checkedAt: '2026-10-08T23:17:21.752Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.317Z'
---

## Overview

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

## Affected

- `handlebars < 4.7.7`

## Remediation

Upgrade past the affected range:

- `handlebars 4.7.7`
