Disclosure summary
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element. When an application precompiles attacker-controlled template text and embeds the generated source directly in an inline script element, a closing script delimiter can end the element and cause following attacker-controlled markup to be parsed and executed. Ordinary server-side rendering and precompiled templates served as external JavaScript files are not affected. This issue is fixed in version 4.7.10.
Source-reported weakness categories
CWE-116
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-xw65-4hp5-5hc7
Open original source · Updated Oct 08, 2026
Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | handlebars | >= 4.0.0, | 4.7.10 |
NIST National Vulnerability Database · NVD-CVE-2026-106444
Open original source · Updated Oct 07, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-10-06T16:17:26-04:00
MODIFIED 2026-10-07T09:58:29-04:00
INGESTED 2026-10-10T20:50:03-04:00