4.7.9
14 years ago
4 days ago
Known vulnerabilities in the handlebars package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in the Note: This is only exploitable if the How to fix Time-of-check Time-of-use (TOCTOU) Race Condition? Upgrade | >=4.0.0 <4.7.9 |
handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Improper Check for Unusual or Exceptional Conditions through the How to fix Improper Check for Unusual or Exceptional Conditions? Upgrade | >=4.0.0 <4.7.9 |
handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output through the CLI precompiler in How to fix Improper Encoding or Escaping of Output? Upgrade | >=4.0.0 <4.7.9 |
handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') via the Note: This is only exploitable if the template uses dynamic partial lookups and the attacker can control the context property used for the lookup. How to fix Access of Resource Using Incompatible Type ('Type Confusion')? Upgrade | >=4.0.0 <4.7.9 |
handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') via the Note: This allows the attacker to inject and run arbitrary commands on the server. This is only exploitable if user-controlled JSON is deserialized and passed directly to the How to fix Access of Resource Using Incompatible Type ('Type Confusion')? Upgrade | >=4.0.0 <4.7.9 |
handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') via manipulation of the Note: This is only exploitable if helpers that accept arbitrary objects are registered and allow mutation of the data context. How to fix Access of Resource Using Incompatible Type ('Type Confusion')? Upgrade | >=4.0.0 <4.7.9 |
handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Prototype Pollution via the Note: This is only exploitable if the attacker knows or can guess the name of a partial reference used in a template. How to fix Prototype Pollution? Upgrade | >=4.0.0 <4.7.9 |
handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source. POC
How to fix Prototype Pollution? Upgrade | <4.7.7 |
handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source. POC
How to fix Remote Code Execution (RCE)? Upgrade | <4.7.7 |
handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Prototype Pollution. Prototype access to the template engine allows for potential code execution. How to fix Prototype Pollution? Upgrade | <4.6.0 |