Description
Versions of handlebars prior to 3.0.8 or 4.5.2 are vulnerable to Arbitrary Code Execution. The package’s lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript in the system.
Recommendation
Update the handlebars package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.0.0, < 4.5.2 < 3.0.8** Patched version(s): **4.5.2 3.0.8**
References
Related Issues
- Arbitrary Code Execution in handlebars - handlebars - GHSA-q2c6-c6pm-g3gh - Vulnerability
- Arbitrary Code Execution in Handlebars - handlebars - CVE-2019-20920
- Trix Editor Arbitrary Code Execution Vulnerability - CVE-2024-34341
- Sandbox Bypass Leading to Arbitrary Code Execution in constantinople - Vulnerability
You might also like:
- Tags:
- npm
- handlebars
Anything's wrong? Let us know Last updated on February 07, 2024


