Handlebars 提供了强大的功能,使用户能够构建语义化的模板。从版本 4.0.0 到 4.7.10,Handlebars.compile() 和 Handlebars.precompile() 方法接受已预解析的 AST(抽象语法树)对象,但仅对部分 PathExpression(路径表达式)、NumberLiteral(数字字面量)和 BooleanLiteral(布尔字面量)值进行验证。此问题绕过了版本 4.7.9 中为修复 CVE-2026-33937 而引入的 AST 验证机制。攻击者若能提供对象而非
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| handlebars-lang | handlebars.js | >= 4.0.0, < 4.7.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| handlebars-lang | handlebars.js | >= 4.0.0, < 4.7.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106445 | 9.2 CRITICAL | Handlebars: JavaScript Injection via Own Property Check Bypass |
| CVE-2026-106444 | 4.7 MEDIUM | Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates |
No comments yet