Get real-time updates on Telegram
CVE-2026-106445: handlebars.js >= 4.0.0, < 4.7.10
Affected technology
handlebars.js · >= 4.0.0, < 4.7.10
handlebars-lang
Component: Not specified by the source
Function: in, through, constructor
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. Vendor/CNA’s CVSS 4.0 assessment (base score 9.2/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-184, CWE-1289
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 02:34:12.333111+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-106445.html