AI description
CVE-2026-106445 is a deny list bypass vulnerability in the Handlebars.js templating engine, affecting versions 4.0.0 through 4.7.9. The library maintains a prototype-access deny list designed to block access to specific properties, such as `constructor`. However, the `lookupProperty` function returns `Function.prototype.constructor` before applying this deny list because `constructor` is recognized as an own property of `Function.prototype`. An attacker can exploit this flaw if they can render a controlled template with the `allowProtoMethodsByDefault` option enabled and have an accessible function within the template context. By traversing from that function through its prototype to `Function.prototype`, the attacker can bypass the deny list to obtain the `Function` constructor. This allows the execution of arbitrary JavaScript with the privileges of the server application. The issue has been resolved in Handlebars.js version 4.7.10.
- Description
- Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.
- Source
- security-advisories@github.com
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 9.2
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-184
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
7
🚨Critical - Handlebars.js Two RCE Bypasses (CVE-2026-106446, CVE-2026-106445) Two flaws let attackers run arbitrary JavaScript on the server. CVE-2026-106446 bypasses the 4.7.9 AST validation: if compile() or precompile() receives a crafted AST object instead of a string,
@UpwindMDR
7 Oct 2026
44 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 HANDLEBARS.JS PATCHES TWO CRITICAL CODE-EXECUTION FLAWS (CVE-2026-106445, CVE-2026-106446) The Handlebars.js maintainers have released version 4.7.10 to fix two critical JavaScript-injection vulnerabilities in the popular npm templating library. Under specific app https://t
@DailyDarkWeb
7 Oct 2026
3262 Impressions
3 Retweets
9 Likes
2 Bookmarks
1 Reply
1 Quote
Two Handlebars.js vulnerability disclosures (CVE-2026-106445, CVE-2026-106446) enable RCE. Details and PoC are public. Update to 4.7.10 now. #Handlebars #HandlebarsJS #NodeJS #CVE2026106445 #CVE2026106446 #RCE #JavaScript #Vulnerability https://t.co/j8PgK3PrNY
@Daily_CyberSec
7 Oct 2026
184 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes