CVE-2026-106445
Received Received - Intake

Handlebars Prototype Pollution via lookupProperty in 4.0.0-4.7.10

Vulnerability report for CVE-2026-106445, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
handlebars-lang handlebars.js >= 4.0.0, < 4.7.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1289 The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Handlebars versions 4.0.0 to 4.7.9. It involves a flaw in the lookupProperty function that allows an attacker to bypass security restrictions. When allowProtoMethodsByDefault is enabled and a function is accessible in the template context, the attacker can traverse the prototype chain to access Function.prototype.constructor, enabling execution of attacker-controlled JavaScript with the server's privileges.

Impact Analysis

If exploited, this vulnerability could allow an attacker to run malicious JavaScript code on your server with the same privileges as your application. This could lead to unauthorized data access, modification, or deletion, and potentially full system compromise depending on the application's permissions.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating confidentiality and integrity requirements in GDPR and HIPAA. Organizations using vulnerable Handlebars versions may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Upgrade Handlebars to version 4.7.10 or later to address the vulnerability. If using allowProtoMethodsByDefault, disable it and review template contexts for accessible functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106445. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart