AI description
CVE-2026-106446 is an Abstract Syntax Tree (AST) type confusion vulnerability affecting the JavaScript templating library Handlebars.js in versions 4.0.0 through 4.7.9. The flaw resides in the `compile()` and `precompile()` functions, which accept pre-parsed AST objects but only validate specific nodes, such as selected PathExpression, NumberLiteral, and BooleanLiteral values. This incomplete validation allows an attacker who can supply an object instead of a standard template string to bypass previous security controls (specifically the fix for CVE-2026-33937) and inject arbitrary JavaScript expressions into unchecked fields, such as `Program.blockParams.length` or non-string values. When the compiler processes these unchecked values, it emits them directly into the generated JavaScript code. This leads to arbitrary code execution within the server process when the compiled output is rendered or when precompiled output is loaded. Applications that only pass trusted template strings to the compiler are not affected by this issue. The vulnerability has been resolved in Handlebars.js version 4.7.10.
- Description
- Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation introduced in version 4.7.9 for CVE-2026-33937. An attacker who can supply an object instead of a template string can place JavaScript expressions in unchecked values such as Program.blockParams.length, a non-PathExpression parameter depth, a non-string StringLiteral.value, or a non-string PathExpression.original. The compiler emits those values into generated JavaScript, causing code execution in the server process when compile output renders or wherever precompile output is loaded. Applications that pass only template strings are not affected. This issue is fixed in version 4.7.10.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-94
- Hype score
- Not currently trending
Handlebars.jsに重大(Critical)な脆弱性。CVE-2026-106446はCVSSスコア9.8で、ASTでの型の取り違え。CVE-2026-33937の修整の迂回に使用可能。CVE-2026-106445はCVSSスコア9.2で拒否リストの迂回。いずれも最終的にはNode.js上での任意
@__kokumoto
7 Oct 2026
685 Impressions
0 Retweets
4 Likes
1 Bookmark
0 Replies
0 Quotes
🚨Critical - Handlebars.js Two RCE Bypasses (CVE-2026-106446, CVE-2026-106445) Two flaws let attackers run arbitrary JavaScript on the server. CVE-2026-106446 bypasses the 4.7.9 AST validation: if compile() or precompile() receives a crafted AST object instead of a string,
@UpwindMDR
7 Oct 2026
56 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 HANDLEBARS.JS PATCHES TWO CRITICAL CODE-EXECUTION FLAWS (CVE-2026-106445, CVE-2026-106446) The Handlebars.js maintainers have released version 4.7.10 to fix two critical JavaScript-injection vulnerabilities in the popular npm templating library. Under specific app https://t
@DailyDarkWeb
7 Oct 2026
4190 Impressions
3 Retweets
15 Likes
2 Bookmarks
1 Reply
1 Quote
Two Handlebars.js vulnerability disclosures (CVE-2026-106445, CVE-2026-106446) enable RCE. Details and PoC are public. Update to 4.7.10 now. #Handlebars #HandlebarsJS #NodeJS #CVE2026106445 #CVE2026106446 #RCE #JavaScript #Vulnerability https://t.co/j8PgK3PrNY
@Daily_CyberSec
7 Oct 2026
184 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
⚠️ Handlebars fixes a critical code execution vulnerability in version 4.7.10 CVE-2026-106446 A critical flaw (CVSS 9.8) in the widely used Handlebars JavaScript templating library allows code execution on the server when an… #CVE #Handlebars #infosec https://t.co/V2Fa63i
@Orbitaley
6 Oct 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes