AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106446.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 9.8CVSS 3.1 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSAwaiting AnalysisModified Oct 07, 2026

Disclosure summary

Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation introduced in version 4.7.9 for CVE-2026-33937. An attacker who can supply an object instead of a template string can place JavaScript expressions in unchecked values such as Program.blockParams.length, a non-PathExpression parameter depth, a non-string StringLiteral.value, or a non-string PathExpression.original. The compiler emits those values into generated JavaScript, causing code execution in the server process when compile output renders or wherever precompile output is loaded. Applications that pass only template strings are not affected. This issue is fixed in version 4.7.10.

Source-reported weakness categories

CWE-94, CWE-843

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-8r5x-fm3f-whwj

Open original source · Updated Oct 08, 2026

Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937)

Source severity: CRITICAL / 0

EcosystemPackageAffected rangeFirst patched
npmhandlebars>= 4.0.0,4.7.10
NIST National Vulnerability Database · NVD-CVE-2026-106446

Open original source · Updated Oct 07, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-10-06T16:17:26-04:00
MODIFIED 2026-10-07T15:17:32-04:00
INGESTED 2026-10-10T20:50:03-04:00