Incomplete List of Disallowed Inputs Affecting org.webjars.npm:handlebars package, versions [4.7.2,]


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.41% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGWEBJARSNPM-20557396
  • published7 Oct 2026
  • disclosed6 Oct 2026
  • creditBrandon T. Elliott

Introduced: 6 Oct 2026

NewCVE-2026-106445  (opens in a new tab)
CWE-184  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

org.webjars.npm:handlebars is an extension to the Mustache templating language.

Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs in the lookupProperty function in lib/handlebars/runtime.js, which returns the resolved value as soon as Object.prototype.hasOwnProperty.call(parent, propertyName) holds, without consulting the prototype access deny list, and constructor is an own property of every prototype object, so Function.prototype.constructor resolves to Function itself. An attacker can execute code on the server by rendering a template that walks to a prototype and reads its constructor, as in {{lookup (lookup fn "__proto__") "constructor"}}. This requires the attacker to control the template rather than only the data, and compilation with allowProtoMethodsByDefault: true.

Workaround

This vulnerability can be avoided by leaving allowProtoMethodsByDefault at its default of false when compiling untrusted templates.

CVSS Base Scores

version 4.0
version 3.1