CVE-2026-106444: fallo de gravedad media en handlebars-lang handlebars.js
Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.7epss 0.3%
probabilidad de explotación
0.3%top 80% de las CVE
explotación observada
noninguna fuente lo reporta
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element. When an application precompiles attacker-controlled template text and embeds the generated source directly in an inline script element, a closing script delimiter can end the element and cause following attacker-controlled markup to be parsed and executed. Ordinary server-side rendering and precompiled templates served as external JavaScript files are not affected. This issue is fixed in version 4.7.10.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Productos afectados
handlebars-lang · handlebars.jsCVEs relacionadas — handlebars-lang handlebars.js
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-33937CRITICALHandlebars.js has JavaScript Injection via AST Type ConfusionEPSS 1.7%CVE-2026-33938HIGHHandlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-blockEPSS 0.8%CVE-2026-33940HIGHHandlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partialEPSS 0.8%CVE-2026-33939HIGHHandlebars.js has Denial of Service via Malformed Decorator Syntax in Template CompilationEPSS 0.8%CVE-2026-106446CRITICALHandlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams)EPSS 0.6%CVE-2026-106445CRITICALHandlebars: JavaScript Injection via Own Property Check BypassEPSS 0.4%
Referencias
https://github.com/handlebars-lang/handlebars.js/commit/609d1b11c833c9a3e00f56f2f34d22f425446725https://github.com/handlebars-lang/handlebars.js/pull/2185https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-xw65-4hp5-5hc7