CVE-2021-23383Medium· 5.6▾ TwilightPoC availableThe package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 30.8 · likelihood 0.9 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.5%
2 GitHub repos (last check)
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
handlebars < 4.7.7e-series_performance_analyzerUpgrade past the affected range:
handlebars 4.7.7Connected by shared product, vendor, weakness, or advisory.
CVE-2021-23369Medium· 5.6The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
CVE-2026-33941High· 8.2Handlebars provides the power necessary to let users build semantic templates
CVE-2026-33937Critical· 9.8Handlebars provides the power necessary to let users build semantic templates
CVE-2019-20920High· 8.1Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution
CVE-2026-33940High· 8.1Handlebars provides the power necessary to let users build semantic templates
CVE-2026-33939High· 7.5Handlebars provides the power necessary to let users build semantic templates