OsVault/npm/handlebars
npm1 critical

handlebars

20 known vulnerabilities · 1 critical · 3 high

GHSA-442j-39wm-28r2

Handlebars.js has a Property Access Validation Bypass in container.lookup

Published Mar 29, 2026
CVE-2021-23369MEDIUM

Remote code execution in handlebars when compiling templates

Published May 6, 2021
CVE-2019-20920HIGH

Arbitrary Code Execution in Handlebars

Published Feb 10, 2022
CVE-2021-23383MEDIUM

Prototype Pollution in handlebars

Published Feb 10, 2022
CVE-2026-33939

Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation

Published Mar 27, 2026
CVE-2026-33940

Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial

Published Mar 27, 2026
CVE-2026-33937

Handlebars.js has JavaScript Injection via AST Type Confusion

Published Mar 27, 2026
GHSA-7rx3-28cr-v5wh

Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry

Published Mar 29, 2026
CVE-2015-8861MEDIUM

Cross-Site Scripting in handlebars

Published Oct 23, 2018
GHSA-q2c6-c6pm-g3gh

Arbitrary Code Execution in handlebars

Published Sep 4, 2020
CVE-2019-19919CRITICAL

Prototype Pollution in handlebars

Published Dec 26, 2019
CVE-2026-33941

Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options

Published Mar 27, 2026
CVE-2026-33916

Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection

Published Mar 26, 2026
CVE-2026-33938

Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block

Published Mar 27, 2026
GHSA-q42p-pg8m-cqh6

Prototype Pollution in handlebars

Published Jun 5, 2019
CVE-2019-20922HIGH

Regular Expression Denial of Service in Handlebars

Published Feb 10, 2022
GHSA-2cf5-4w76-r9qv

Arbitrary Code Execution in handlebars

Published Sep 4, 2020
GHSA-g9r4-xpmj-mj65

Prototype Pollution in handlebars

Published Sep 4, 2020
CVE-2021-32820HIGH

Insecure template handling in Express-handlebars

Published Feb 10, 2022
MAL-2022-2719

Malicious code in ember-handlebars (npm)

Published Jun 20, 2022
Check your entire dependency tree at onceRun dependency scan →