CVE-2021-23383
MEDIUMHandlebars < 4.7.7 - Prototype Pollution
Title source: ruleDescription
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
Exploits (2)
References (6)
Scores
CVSS v3
5.6
EPSS
0.0318
EPSS Percentile
87.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-1321
Status
published
Products (3)
handlebarsjs/handlebars
< 4.7.7
netapp/e-series_performance_analyzer
npm/handlebars
0 - 4.7.7npm
Published
May 04, 2021
Tracked Since
Feb 18, 2026