
🚨 HANDLEBARS.JS PATCHES TWO CRITICAL CODE-EXECUTION FLAWS (CVE-2026-106445, CVE-2026-106446) The Handlebars.js maintainers have released version 4.7.10 to fix two critical JavaScript-injection vulnerabilities in the popular npm templating library. Under specific app configurations, both can let an attacker run arbitrary JavaScript in the server's Node.js process. • CVE-2026-106446 (CVSS 3.1 9.8): compile() and precompile() accept pre-parsed AST objects, and the AST validation added in 4.7.9 can be bypassed. If untrusted input reaches them as an object (e.g. a JSON request body field) instead of a string, injected code runs on render; with precompile() it runs wherever the output is loaded, including users' browsers • CVE-2026-106445 (CVSS 4.0 9.2): a prototype-access deny-list bypass exposes the Function constructor when an attacker can render a controlled template with allowProtoMethodsByDefault enabled and a function in the template context • Affected: Handlebars.js 4.0.0 through 4.7.9 • Fixed: Handlebars.js 4.7.10 Remediation: • Upgrade to Handlebars.js 4.7.10 or later • Make sure only template strings, never objects, reach compile() or precompile() • Do not enable allowProtoMethodsByDefault for untrusted templates and data ⚠️ Analyst Note: Exposure depends on how an app uses Handlebars: apps that only pass template strings are not affected by CVE-2026-106446, and CVE-2026-106445 requires allowProtoMethodsByDefault to be enabled. Both GitHub advisories include proof-of-concept code. Neither the advisories nor the CVE records report in-the-wild exploitation. Sources: https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-p8wg-vrv2-v86f https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-8r5x-fm3f-whwj #DDW #DarkWeb #CyberSecurity #Handlebars #NodeJS #CVE #PatchNow




