CVE-2026-106446

Published Oct 6, 2026

Last updated 33 minutes ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-106446 is an Abstract Syntax Tree (AST) type confusion vulnerability affecting the JavaScript templating library Handlebars.js in versions 4.0.0 through 4.7.9. The flaw resides in the `compile()` and `precompile()` functions, which accept pre-parsed AST objects but only validate specific nodes, such as selected PathExpression, NumberLiteral, and BooleanLiteral values. This incomplete validation allows an attacker who can supply an object instead of a standard template string to bypass previous security controls (specifically the fix for CVE-2026-33937) and inject arbitrary JavaScript expressions into unchecked fields, such as `Program.blockParams.length` or non-string values. When the compiler processes these unchecked values, it emits them directly into the generated JavaScript code. This leads to arbitrary code execution within the server process when the compiled output is rendered or when precompiled output is loaded. Applications that only pass trusted template strings to the compiler are not affected by this issue. The vulnerability has been resolved in Handlebars.js version 4.7.10.

Description
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation introduced in version 4.7.9 for CVE-2026-33937. An attacker who can supply an object instead of a template string can place JavaScript expressions in unchecked values such as Program.blockParams.length, a non-PathExpression parameter depth, a non-string StringLiteral.value, or a non-string PathExpression.original. The compiler emits those values into generated JavaScript, causing code execution in the server process when compile output renders or wherever precompile output is loaded. Applications that pass only template strings are not affected. This issue is fixed in version 4.7.10.
Source
security-advisories@github.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-94

Social media

Hype score
Not currently trending
  1. Handlebars.jsに重大(Critical)な脆弱性。CVE-2026-106446はCVSSスコア9.8で、ASTでの型の取り違え。CVE-2026-33937の修整の迂回に使用可能。CVE-2026-106445はCVSSスコア9.2で拒否リストの迂回。いずれも最終的にはNode.js上での任意

    @__kokumoto

    7 Oct 2026

    685 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  2. 🚨Critical - Handlebars.js Two RCE Bypasses (CVE-2026-106446, CVE-2026-106445) Two flaws let attackers run arbitrary JavaScript on the server. CVE-2026-106446 bypasses the 4.7.9 AST validation: if compile() or precompile() receives a crafted AST object instead of a string,

    @UpwindMDR

    7 Oct 2026

    56 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 🚨 HANDLEBARS.JS PATCHES TWO CRITICAL CODE-EXECUTION FLAWS (CVE-2026-106445, CVE-2026-106446) The Handlebars.js maintainers have released version 4.7.10 to fix two critical JavaScript-injection vulnerabilities in the popular npm templating library. Under specific app https://t

    @DailyDarkWeb

    7 Oct 2026

    4190 Impressions

    3 Retweets

    15 Likes

    2 Bookmarks

    1 Reply

    1 Quote

  4. Two Handlebars.js vulnerability disclosures (CVE-2026-106445, CVE-2026-106446) enable RCE. Details and PoC are public. Update to 4.7.10 now. #Handlebars #HandlebarsJS #NodeJS #CVE2026106445 #CVE2026106446 #RCE #JavaScript #Vulnerability https://t.co/j8PgK3PrNY

    @Daily_CyberSec

    7 Oct 2026

    184 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ Handlebars fixes a critical code execution vulnerability in version 4.7.10 CVE-2026-106446 A critical flaw (CVSS 9.8) in the widely used Handlebars JavaScript templating library allows code execution on the server when an… #CVE #Handlebars #infosec https://t.co/V2Fa63i

    @Orbitaley

    6 Oct 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes