CVE-2026-106445Critical· 9.2▾ MidnightHandlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor i…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106446Critical· 9.8Handlebars provides the power necessary to let users build semantic templates
CVE-2026-106444Medium· 4.7Handlebars provides the power necessary to let users build semantic templates
CVE-2026-106442High· 7.8Hydra is a framework for elegantly configuring complex applications
CVE-2026-106218High· 8.8In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
CVE-2026-105791High· 7.5Microsoft UFO is an open-source framework for intelligent automation across devices and platforms
CVE-2026-105789Medium· 5.4Microsoft UFO is an open-source framework for intelligent automation across devices and platforms