handlebars.js vulnerabilities
CVEs whose affected-version data names the handlebars.js package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-106445Critical· 9.2Handlebars provides the power necessary to let users build semantic templates
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor i…
CVE-2026-106446Critical· 9.8Handlebars provides the power necessary to let users build semantic templates
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberL…
CVE-2026-106444Medium· 4.7PoCHandlebars provides the power necessary to let users build semantic templates
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaSc…