CVE-2026-33939Patch(handlebarsjs / handlebars)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch handlebarsjs handlebars systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the compiled template calls `lookupProperty(decorators, "n")`, which returns `undefined`. The runtime then immediately invokes the result as a function, causing an unhandled `TypeError: ... is not a function` that crashes the Node.js process. Any application that compiles user-supplied templates without wrapping the call in a `try/catch` is vulnerable to a single-request Denial of Service. Version 4.7.9 fixes the issue. Some workarounds are available. Wrap compilation and rendering in `try/catch`. Validate template input before passing it to `compile()`; reject templates containing decorator syntax (`{{*...}}`) if decorators are not used in your application. Use the pre-compilation workflow; compile templates at build time and serve only pre-compiled templates; do not call `compile()` at request time.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754CWE-248

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • handlebars

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-27); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
handlebars

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1PoC Mentioned / Linked · 2026-03-27: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 103-2703-28
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-271
Patch1
2026-03-281
General1
Full discourse2 posts
  • trace37@trace37_labs
    Patch

    CVE-2026-33939 has been published based on trace37 research and findings. Denial of Service in Handlebars.js (4.0.0 through 4.7.8), patched in 4.7.9. Handlebars has over 2 million weekly downloads on npm. I discovered that referencing an unregistered decorator in a Handlebars template (e.g. {{*n}}) crashes the Node.js process with an unhandled TypeError. A single malicious request to any endpoint compiling user-supplied templates takes down the server. The root cause: the compiled code calls the result of a property lookup as a function without checking if it exists — something Handlebars already handles correctly for missing helpers, but not for decorators. The maintainer patched it promptly. Full writeup: https://labs.trace37.com/cves/cve-2026-33939/ GitHub Advisory: https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-9cx6-37pm-9jff If you use Handlebars in production, upgrade to 4.7.9. #CVE #security #vulnerability #nodejs #opensource

    Post summary

    CVE‑2026‑33939 causes a denial‑of‑service in Handlebars.js when using an unregistered decorator. The vulnerability has been patched in version 4.7.9; upgrading is recommended.

    01091581
    828 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33939 Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax r… https://www.cve.org/CVERecord?id=CVE-2026-33939

    Post summary

    The snippet merely notes the existence of CVE‑2026‑33939 in Handlebars with a link to its CVE record, providing no additional specifics.

    00000101
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphandlebarsjshandlebars-node.js-

Explore more