CVE-2026-106444
MEDIUM
4,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element. When an application precompiles attacker-controlled template text and embeds the generated source directly in an inline script element, a closing script delimiter can end the element and cause following attacker-controlled markup to be parsed and executed. Ordinary server-side rendering and precompiled templates served as external JavaScript files are not affected. This issue is fixed in version 4.7.10.
116
Improper Encoding or Escaping of Output
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Access Control
Potential Impacts:
Modify Application Data
Execute Unauthorized Code Or Commands
Bypass Protection Mechanism
Applicable Platforms
Technologies:
Not Technology-Specific, AI/ML, Database Server, Web Server
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-xw65-…
https://github.com/handlebars-lang/handlebars.js/commit/609d1b11c833c9a3e00f56f…
https://github.com/handlebars-lang/handlebars.js/pull/2185
https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-xw65-…