Description
Handlebars.js before 4.1.0 has Remote Code Execution (RCE)
Recommendation
Update the handlebars package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.1.0
- Patched version(s): 4.1.0
References
Related Issues
- Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - CVE-2026-41264
- Arbitrary Code Execution in handlebars - handlebars - GHSA-q2c6-c6pm-g3gh - Vulnerability
- JSONPath Plus Remote Code Execution (RCE) Vulnerability - CVE-2024-21534
- @saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defst - Vulnerability
You might also like:
- Tags:
- npm
- handlebars
Anything's wrong? Let us know Last updated on January 09, 2023


