Description
Handlebars.compile() accepts a pre-parsed AST object in addition to a template string. The value field of a NumberLiteral AST node is emitted directly into the generated JavaScript without quoting or sanitization.
Recommendation
Update the handlebars package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.0.0, <= 4.7.8
- Patched version(s): 4.7.9
References
Could your website be exposed too?
SmartScanner can check your website for Handlebars.js has JavaScript Injection via AST Type Confusion and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial - CVE-2026-33940
- Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block - CVE-2026-33938
- Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options - CVE-2026-33941
- js-toml has silent type confusion via falsy-primitive duplicate-key bypass - CVE-2026-50029


