Description
Versions of handlebars prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects’ __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Recommendation
Update the handlebars package to the latest compatible version. Followings are version details:
Affected version(s): **< 3.0.8 >= 4.0.0, < 4.3.0** Patched version(s): **3.0.8 4.3.0**
References
Could your website be exposed too?
SmartScanner can check your website for Prototype Pollution in handlebars and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Prototype Pollution in handlebars - handlebars - CVE-2021-23383
- Prototype Pollution in dot-object - CVE-2019-10793
- Prototype Pollution in undefsafe - CVE-2019-10795
- Prototype Pollution in chartkick - CVE-2019-18841


