VendorsHandlebarsjshandlebarsall versions
Vulnerabilities

Handlebarsjs Handlebars

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2021-23369
Remote Code Execution (RCE)
Published 2021-04-12 · Modified
9.8EPSS 0.070
CVE-2021-23383
Prototype Pollution
Published 2021-05-04 · Modified
9.8EPSS 0.045
CVE-2026-33937
Handlebars.js has JavaScript Injection via AST Type Confusion
Published 2026-03-27 · Modified
9.8EPSS 0.017
CVE-2026-33941
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
Published 2026-03-27 · Modified
8.2EPSS 0.002
CVE-2019-20920
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).
Published 2020-09-30 · Modified
8.1EPSS 0.032
CVE-2026-33938
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
Published 2026-03-27 · Modified
8.1EPSS 0.008
CVE-2026-33940
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
Published 2026-03-27 · Modified
8.1EPSS 0.008
CVE-2019-20922
Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.
Published 2020-09-30 · Modified
7.8EPSS 0.038
CVE-2026-33939
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
Published 2026-03-27 · Modified
7.5EPSS 0.008
CVE-2026-33916
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
Published 2026-03-27 · Analyzed
4.7EPSS 0.004