Handlebars
19 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Handlebars, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Handlebars CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 8 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High6
- Medium4
Latest CVEs
The 15 most recently published vulnerabilities affecting Handlebars.
- GHSA-7rx3-28cr-v5whHandlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry—
- GHSA-442j-39wm-28r2Handlebars.js has a Property Access Validation Bypass in container.lookup—
- CVE-2026-33941Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options8.2
- CVE-2026-33940Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial8.1
- CVE-2026-33939Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation7.5
- CVE-2026-33938Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block8.1
- CVE-2026-33937Handlebars.js has JavaScript Injection via AST Type Confusion9.8
- CVE-2026-33916Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection4.7
- CVE-2021-23383Prototype Pollution5.6
- CVE-2021-23369Remote Code Execution (RCE)5.6
- CVE-2019-20920Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute a...8.1
- CVE-2019-20922Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may all...7.5
- GHSA-q2c6-c6pm-g3ghArbitrary Code Execution in handlebars—
- GHSA-g9r4-xpmj-mj65Prototype Pollution in handlebars—
- GHSA-2cf5-4w76-r9qvArbitrary Code Execution in handlebars—
Product grouping is registry-driven, with AI assist and human review. How it works