Description
Handlebars.js before 4.1.0 has Remote Code Execution (RCE)
Recommendation
Update the handlebars package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.1.0
- Patched version(s): 4.1.0
References
Could your website be exposed too?
SmartScanner can check your website for Remote code execution in Handlebars.js and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - CVE-2026-41264
- Arbitrary Code Execution in handlebars - handlebars - GHSA-q2c6-c6pm-g3gh - Vulnerability
- JSONPath Plus Remote Code Execution (RCE) Vulnerability - CVE-2024-21534
- @saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defst - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


