Description
Versions of handlebars prior to 3.0.8 or 4.5.3 are vulnerable to Arbitrary Code Execution. The package’s lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript in the system. It is due to an incomplete fix for a previous issue.
Recommendation
Update the handlebars package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.0.0, < 4.5.3 < 3.0.8** Patched version(s): **4.5.3 3.0.8**
References
Could your website be exposed too?
SmartScanner can check your website for Arbitrary Code Execution in handlebars - handlebars - GHSA-q2c6-c6pm-g3gh and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-876r-hj45-fw7g - Vulnerability
- Arbitrary Code Execution in handlebars - Vulnerability
- Trix Editor Arbitrary Code Execution Vulnerability - CVE-2024-34341
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-hgch-jjmr-gp7w - CVE-2019-10760


