CVE-2026-106445

LOWCVSS 9.2 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184CWE-1289

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-10-07: 510-07
Referenced assets5 URLs
Full discourse5 posts
  • Dark Web Intelligence@DailyDarkWeb

    🚨 HANDLEBARS.JS PATCHES TWO CRITICAL CODE-EXECUTION FLAWS (CVE-2026-106445, CVE-2026-106446) The Handlebars.js maintainers have released version 4.7.10 to fix two critical JavaScript-injection vulnerabilities in the popular npm templating library. Under specific app configurations, both can let an attacker run arbitrary JavaScript in the server's Node.js process. • CVE-2026-106446 (CVSS 3.1 9.8): compile() and precompile() accept pre-parsed AST objects, and the AST validation added in 4.7.9 can be bypassed. If untrusted input reaches them as an object (e.g. a JSON request body field) instead of a string, injected code runs on render; with precompile() it runs wherever the output is loaded, including users' browsers • CVE-2026-106445 (CVSS 4.0 9.2): a prototype-access deny-list bypass exposes the Function constructor when an attacker can render a controlled template with allowProtoMethodsByDefault enabled and a function in the template context • Affected: Handlebars.js 4.0.0 through 4.7.9 • Fixed: Handlebars.js 4.7.10 Remediation: • Upgrade to Handlebars.js 4.7.10 or later • Make sure only template strings, never objects, reach compile() or precompile() • Do not enable allowProtoMethodsByDefault for untrusted templates and data ⚠️ Analyst Note: Exposure depends on how an app uses Handlebars: apps that only pass template strings are not affected by CVE-2026-106446, and CVE-2026-106445 requires allowProtoMethodsByDefault to be enabled. Both GitHub advisories include proof-of-concept code. Neither the advisories nor the CVE records report in-the-wild exploitation. Sources: https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-p8wg-vrv2-v86f https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-8r5x-fm3f-whwj #DDW #DarkWeb #CyberSecurity #Handlebars #NodeJS #CVE #PatchNow

    1311423.8K
    206.8K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Two Handlebars.js vulnerability disclosures (CVE-2026-106445, CVE-2026-106446) enable RCE. Details and PoC are public. Update to 4.7.10 now. #Handlebars #HandlebarsJS #NodeJS #CVE2026106445 #CVE2026106446 #RCE #JavaScript #Vulnerability https://securityonline.info/handlebars-js-vulnerability-rce-poc/

    12030422
    13.0K followersView on X
  • Netlas.io@Netlas_io

    CVE-2026-106445 & CVE-2026-106446: Two RCE flaws in Handlebars.js, up to 9.8 rating ‍🔥 Two recently disclosed vulnerabilities in Handlebars.js allow an attacker to run arbitrary JavaScript on the server. Both the technical details and PoC exploit code are now public! 👉 https://nt.ls/KMYBH

    01001228
    7.7K followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Handlebars.js Two RCE Bypasses (CVE-2026-106446, CVE-2026-106445) Two flaws let attackers run arbitrary JavaScript on the server. CVE-2026-106446 bypasses the 4.7.9 AST validation: if compile() or precompile() receives a crafted AST object instead of a string, unchecked fields are written straight into the generated code. CVE-2026-106445 bypasses the prototype deny list: a controlled template can reach the Function constructor through Function.prototype when allowProtoMethodsByDefault is enabled. 👉Upgrade to Handlebars.js 4.7.10.

    1001047
    311 followersView on X
  • NEXSIGHT@NEXSIGHTNEWS

    Handlebars.jsにサーバーで任意コードが実行される重大な脆弱性2件、修正版4.7.10を公開 — 月間ダウンロード1.7億件超、概念実証も出回る https://cyber.nexsight.co/articles/2026/10/07/handlebars-js-rce-cve-2026-106445-106446-4710-2026-10-07/

    00000164
    76 followersView on X

Explore more