CVE-2026-106445: critical vulnerability in handlebars-lang handlebars.js
Handlebars: JavaScript Injection via Own Property Check Bypass
Published
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.2epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
handlebars-lang · handlebars.jsRelated CVEs — handlebars-lang handlebars.js
In the same product, most dangerous first.
CVE-2026-33937CRITICALHandlebars.js has JavaScript Injection via AST Type ConfusionEPSS 1.7%CVE-2026-33938HIGHHandlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-blockEPSS 0.8%CVE-2026-33940HIGHHandlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partialEPSS 0.8%CVE-2026-33939HIGHHandlebars.js has Denial of Service via Malformed Decorator Syntax in Template CompilationEPSS 0.8%CVE-2026-106446CRITICALHandlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams)EPSS 0.6%CVE-2026-33916MEDIUMHandlebars.js has Prototype Pollution Leading to XSS through Partial Template InjectionEPSS 0.4%
References
https://github.com/handlebars-lang/handlebars.js/commit/ceec388abe1d1aac8f6369860d5f390fa71ef4fahttps://github.com/handlebars-lang/handlebars.js/pull/2185https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-p8wg-vrv2-v86f