Skip to main content

Vendor/product archive

handlebarsjs / handlebars CVEs

Beta · best-effort

10 CVEs tagged to handlebarsjs / handlebars1 Critical, 6 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-33941

Published Mar 27, 2026

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler…

CVSS 8.2 · High
evidence mentions
9
Buzz score
41.0
Vendor/product tagsBeta · best-effort

CVE-2026-33940

Published Mar 27, 2026

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all cond…

CVSS 8.1 · High
evidence mentions
9
Buzz score
41.0
Vendor/product tagsBeta · best-effort

CVE-2026-33939

Published Mar 27, 2026

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an…

CVSS 7.5 · High
evidence mentions
9
Buzz score
41.0
Vendor/product tagsBeta · best-effort

CVE-2026-33938

Published Mar 27, 2026

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template dat…

CVSS 8.1 · High
evidence mentions
9
Buzz score
41.0
Vendor/product tagsBeta · best-effort

CVE-2026-33937

Published Mar 27, 2026

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-33916

Published Mar 27, 2026

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names…

CVSS 4.7 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2021-23369

Published Apr 12, 2021

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20922

Published Sep 30, 2020

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templ…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20920

Published Sep 30, 2020

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templa…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1