Arbitrary Code Execution in handlebars - handlebars - GHSA-q2c6-c6pm-g3gh
- Severity:
- High
Description
Versions of handlebars prior to 3.0.8 or 4.5.3 are vulnerable to Arbitrary Code Execution. The package’s lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript in the system. It is due to an incomplete fix for a previous issue.
Recommendation
Update the handlebars package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.0.0, < 4.5.3 < 3.0.8** Patched version(s): **4.5.3 3.0.8**
References
Related Issues
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-876r-hj45-fw7g - Vulnerability
- Arbitrary Code Execution in handlebars - Vulnerability
- Trix Editor Arbitrary Code Execution Vulnerability - CVE-2024-34341
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-hgch-jjmr-gp7w - CVE-2019-10760
You might also like:
- Tags:
- npm
- handlebars
Anything's wrong? Let us know Last updated on January 09, 2023


