Handlebars 提供了构建语义化模板所需的功能。在版本 4.0.0 到 4.7.10 之间, 函数在应用原型访问禁止列表(prototype-access deny list)之前,会返回 ,这是因为 是 的一个自有属性(own property)。当攻击者能够渲染一个经过控制的模板,并且模板上下文中存在一个可访问的函数,同时启用了 选项时,模板可以通过该函数沿原型链遍历至 ,然后绕过自有属性限制获取到 构造函数。这使得攻击者可以在服务器应用程序的特权级别下执行其控制的 JavaScript 代码。此问题已在
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| handlebars-lang | handlebars.js | >= 4.0.0, < 4.7.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| handlebars-lang | handlebars.js | >= 4.0.0, < 4.7.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106446 | 9.8 CRITICAL | Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams) |
| CVE-2026-106444 | 4.7 MEDIUM | Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates |
No comments yet