---
id: CVE-2021-23383
title: >-
  The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when
  selecting certain compiling options to compile templates coming from an
  untrusted source.
summary: >-
  The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when
  selecting certain compiling options to compile templates coming from an
  untrusted source.
severity: medium
cvss: 5.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-1321
vendor: handlebarsjs
product: handlebars
affected:
  - handlebars < 4.7.7
  - e-series_performance_analyzer
patched:
  - handlebars 4.7.7
published: '2021-05-04'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:07.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-23383'
references:
  - url: >-
      https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427
    label: report@snyk.io
  - url: 'https://security.netapp.com/advisory/ntap-20210618-0007/'
    label: report@snyk.io
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1279031'
    label: report@snyk.io
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1279032'
    label: report@snyk.io
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1279030'
    label: report@snyk.io
  - url: 'https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1279029'
    label: report@snyk.io
  - url: >-
      https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210618-0007/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1279031'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1279032'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1279030'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1279029'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.04506
epssPercentile: 0.91266
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/dn9uy3n/Check-CVE-2021-23383'
    - 'https://github.com/fazilbaig1/CVE-2021-23383'
  checkedAt: '2026-10-08T23:17:21.752Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.318Z'
---

## Overview

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

## Affected

- `handlebars < 4.7.7`
- `e-series_performance_analyzer`

## Remediation

Upgrade past the affected range:

- `handlebars 4.7.7`
