---
id: CVE-2026-103088
title: Handlebars.java before 4.5.5 allows directory traversal
summary: >-
  Handlebars.java before 4.5.5 allows directory traversal. In
  handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for
  CVE-2026-63490 validates template locations as raw percent-encoded strings,
  whereas the template file is opene…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-24
vendor: jknack
product: handlebars.java
affected:
  - handlebars.java >= 4.5.3 < 4.5.5
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T02:16:57.340'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103088'
references:
  - url: >-
      https://github.com/jknack/handlebars.java/commit/f6ae3979917d05bef07f00befb4013ef00503660
    label: cve@mitre.org
  - url: 'https://github.com/jknack/handlebars.java/releases/tag/v4.5.5'
    label: cve@mitre.org
  - url: >-
      https://github.com/jknack/handlebars.java/security/advisories/GHSA-pvrx-3g7m-fpgv
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T01:54:42.730Z'
---

## Overview

Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
