CVE-2026-106445

Published Oct 6, 2026

Last updated 15 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-106445 is a deny list bypass vulnerability in the Handlebars.js templating engine, affecting versions 4.0.0 through 4.7.9. The library maintains a prototype-access deny list designed to block access to specific properties, such as `constructor`. However, the `lookupProperty` function returns `Function.prototype.constructor` before applying this deny list because `constructor` is recognized as an own property of `Function.prototype`. An attacker can exploit this flaw if they can render a controlled template with the `allowProtoMethodsByDefault` option enabled and have an accessible function within the template context. By traversing from that function through its prototype to `Function.prototype`, the attacker can bypass the deny list to obtain the `Function` constructor. This allows the execution of arbitrary JavaScript with the privileges of the server application. The issue has been resolved in Handlebars.js version 4.7.10.

Description
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.
Source
security-advisories@github.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-184

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

7