在 Handlebars.java 4.5.5 之前的版本中存在目录遍历漏洞。具体而言,在 handlebars-springmvc 4.5.3 和 4.5.4 版本中,针对 CVE-2026-63490 的路径 containment(路径隔离)修复机制存在缺陷:系统在对模板位置进行校验时,将其视为原始百分比编码(percent-encoded)字符串;然而,实际打开模板文件时,却通过 URL 处理程序对路径进行了百分比解码。 在采用 模板前缀且视图名称源自用户请求的 Spring MVC 应用中,攻击者可利用形
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jknack | handlebars.java | 4.5.3< 4.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jknack | handlebars.java | 4.5.3 ~ 4.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet