Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106445— Handlebars: JavaScript Injection via Own Property Check Bypass

Quick assessment

Affected
handlebars-lang handlebars.js
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Handlebars 提供了构建语义化模板所需的功能。在版本 4.0.0 到 4.7.10 之间, 函数在应用原型访问禁止列表(prototype-access deny list)之前,会返回 ,这是因为 是 的一个自有属性(own property)。当攻击者能够渲染一个经过控制的模板,并且模板上下文中存在一个可访问的函数,同时启用了 选项时,模板可以通过该函数沿原型链遍历至 ,然后绕过自有属性限制获取到 构造函数。这使得攻击者可以在服务器应用程序的特权级别下执行其控制的 JavaScript 代码。此问题已在

CVSS 9.2 · Critical

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
handlebars-lang handlebars.js >= 4.0.0, < 4.7.10 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106445

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Handlebars: JavaScript Injection via Own Property Check Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不完整的黑名单
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
handlebars-lang handlebars.js >= 4.0.0, < 4.7.10 -

II. Public POCs for CVE-2026-106445

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106445

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-106445 (2)

Vendor Advisories for CVE-2026-106445 (1)

Vendor Pages for CVE-2026-106445 (1)

Same Patch Batch · handlebars-lang · 2026-10-06 · 3 CVEs total

CVE-2026-106446 9.8 CRITICAL Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams)
CVE-2026-106444 4.7 MEDIUM Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates

IV. Related Vulnerabilities

V. Comments for CVE-2026-106445

No comments yet


Leave a comment