handlebars-lang has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was October 2026 with 3. The median CVSS is 9.2 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.2
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Weakness classes
Products
- handlebars.js 3
Worst active — by depth score
CVE-2026-106446Critical· 9.8Handlebars provides the power necessary to let users build semantic templates54CVE-2026-106445Critical· 9.2Handlebars provides the power necessary to let users build semantic templates51CVE-2026-106444Medium· 4.7Handlebars provides the power necessary to let users build semantic templates38
handlebars-lang vulnerabilities
CVEs affecting handlebars-lang, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-106445Critical· 9.2Handlebars provides the power necessary to let users build semantic templates
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor i…
CVE-2026-106446Critical· 9.8Handlebars provides the power necessary to let users build semantic templates
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberL…
CVE-2026-106444Medium· 4.7PoCHandlebars provides the power necessary to let users build semantic templates
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaSc…