Description
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript.
Recommendation
Update the handlebars package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.0.0, < 4.5.3 < 3.0.8** Patched version(s): **4.5.3 3.0.8**
References
Related Issues
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - CVE-2019-10769
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-hgch-jjmr-gp7w - CVE-2019-10760
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-r3x4-wr4h-pw33 - CVE-2019-10759
- Arbitrary Code Execution in underscore - CVE-2021-23358
You might also like:
- Tags:
- npm
- handlebars
Anything's wrong? Let us know Last updated on November 29, 2023


