Description
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript.
Recommendation
Update the handlebars package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.0.0, < 4.5.3 < 3.0.8** Patched version(s): **4.5.3 3.0.8**
References
Could your website be exposed too?
SmartScanner can check your website for Arbitrary Code Execution in Handlebars - handlebars and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - CVE-2019-10769
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-hgch-jjmr-gp7w - CVE-2019-10760
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-r3x4-wr4h-pw33 - CVE-2019-10759
- Arbitrary Code Execution in underscore - CVE-2021-23358


