CVE-2026-103088
Deferred Deferred - Pending Action

Path Traversal in Handlebars.java

Vulnerability report for CVE-2026-103088, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: MITRE

Description

Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
jknack handlebars.java to 4.5.5 (exc)
jknack handlebars-springmvc 4.5.3
jknack handlebars-springmvc 4.5.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-24 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Handlebars.java versions 4.5.3 and 4.5.4 affecting the handlebars-springmvc library. The issue occurs because path validation checks are performed on percent-encoded strings while file access uses percent-decoded paths. Attackers can exploit this by submitting encoded traversal sequences like %2e%2e/ to bypass security checks and read files outside the intended template directory in Spring MVC applications.

Detection Guidance

To detect this vulnerability, check if your system uses handlebars-springmvc versions 4.5.3 or 4.5.4. Inspect application logs for requests containing percent-encoded traversal sequences like %2e%2e/. Verify if file: URL prefixes are used in Spring MVC applications with request-derived view names.

Impact Analysis

An attacker could read sensitive files on the server, including configuration files, source code, or other restricted resources. The impact depends on the suffix configuration: with default .hbs suffix, only template files are exposed, but with empty suffix, any file can be accessed. This requires a specific configuration using file: URL prefixes and request-derived view names.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Unauthorized file access may result in data breaches that require regulatory reporting and could lead to compliance violations and penalties.

Mitigation Strategies

Upgrade to handlebars-springmvc version 4.5.5 or later. If using file: URL prefixes in Spring MVC, ensure path validation properly decodes percent-encoded sequences before containment checks. Review and restrict file access permissions for template directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103088. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart