CVE-2026-106446

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation introduced in version 4.7.9 for CVE-2026-33937. An attacker who can supply an object instead of a template string can place JavaScript expressions in unchecked values such as Program.blockParams.length, a non-PathExpression parameter depth, a non-string StringLiteral.value, or a non-string PathExpression.original. The compiler emits those values into generated JavaScript, causing code execution in the server process when compile output renders or wherever precompile output is loaded. Applications that pass only template strings are not affected. This issue is fixed in version 4.7.10.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-843

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-10-07: 410-07
Referenced assets4 URLs
Full discourse4 posts
  • Dark Web Intelligence@DailyDarkWeb

    🚨 HANDLEBARS.JS PATCHES TWO CRITICAL CODE-EXECUTION FLAWS (CVE-2026-106445, CVE-2026-106446) The Handlebars.js maintainers have released version 4.7.10 to fix two critical JavaScript-injection vulnerabilities in the popular npm templating library. Under specific app configurations, both can let an attacker run arbitrary JavaScript in the server's Node.js process. • CVE-2026-106446 (CVSS 3.1 9.8): compile() and precompile() accept pre-parsed AST objects, and the AST validation added in 4.7.9 can be bypassed. If untrusted input reaches them as an object (e.g. a JSON request body field) instead of a string, injected code runs on render; with precompile() it runs wherever the output is loaded, including users' browsers • CVE-2026-106445 (CVSS 4.0 9.2): a prototype-access deny-list bypass exposes the Function constructor when an attacker can render a controlled template with allowProtoMethodsByDefault enabled and a function in the template context • Affected: Handlebars.js 4.0.0 through 4.7.9 • Fixed: Handlebars.js 4.7.10 Remediation: • Upgrade to Handlebars.js 4.7.10 or later • Make sure only template strings, never objects, reach compile() or precompile() • Do not enable allowProtoMethodsByDefault for untrusted templates and data ⚠️ Analyst Note: Exposure depends on how an app uses Handlebars: apps that only pass template strings are not affected by CVE-2026-106446, and CVE-2026-106445 requires allowProtoMethodsByDefault to be enabled. Both GitHub advisories include proof-of-concept code. Neither the advisories nor the CVE records report in-the-wild exploitation. Sources: https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-p8wg-vrv2-v86f https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-8r5x-fm3f-whwj #DDW #DarkWeb #CyberSecurity #Handlebars #NodeJS #CVE #PatchNow

    1311423.8K
    206.8K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Two Handlebars.js vulnerability disclosures (CVE-2026-106445, CVE-2026-106446) enable RCE. Details and PoC are public. Update to 4.7.10 now. #Handlebars #HandlebarsJS #NodeJS #CVE2026106445 #CVE2026106446 #RCE #JavaScript #Vulnerability https://securityonline.info/handlebars-js-vulnerability-rce-poc/

    12030422
    13.0K followersView on X
  • Netlas.io@Netlas_io

    CVE-2026-106445 & CVE-2026-106446: Two RCE flaws in Handlebars.js, up to 9.8 rating ‍🔥 Two recently disclosed vulnerabilities in Handlebars.js allow an attacker to run arbitrary JavaScript on the server. Both the technical details and PoC exploit code are now public! 👉 https://nt.ls/KMYBH

    01001228
    7.7K followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Handlebars.js Two RCE Bypasses (CVE-2026-106446, CVE-2026-106445) Two flaws let attackers run arbitrary JavaScript on the server. CVE-2026-106446 bypasses the 4.7.9 AST validation: if compile() or precompile() receives a crafted AST object instead of a string, unchecked fields are written straight into the generated code. CVE-2026-106445 bypasses the prototype deny list: a controlled template can reach the Function constructor through Function.prototype when allowProtoMethodsByDefault is enabled. 👉Upgrade to Handlebars.js 4.7.10.

    1001047
    311 followersView on X

Explore more