CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-106445: handlebars.js >= 4.0.0, < 4.7.10

Affected technology

handlebars.js · >= 4.0.0, < 4.7.10
handlebars-lang

Component: Not specified by the source
Function: in, through, constructor

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. Vendor/CNA’s CVSS 4.0 assessment (base score 9.2/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-184, CWE-1289
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-106445.html